Kiel · Schleswig-Holstein · Germany-wide Mon–Fri 9–17 CET
+49 15778716239 info@tsbsec.de
Security

Report a vulnerability

We take reports of vulnerabilities in our own systems seriously and handle them according to the principle of coordinated disclosure. This page describes how to reach us and what you can expect from us.

Last updated: September 2026

Scope

This policy applies to systems operated by TSB Top Sec Bau GmbH – in particular the website tsbsec.de and the associated e-mail infrastructure. Systems of our customers are explicitly excluded; we test those only with written authorisation.

How to report a vulnerability

Write to info@tsbsec.de. Please encrypt confidential details with our PGP key (see below). Helpful information: affected system, type of vulnerability, steps to reproduce and – if available – a proof of concept.

A machine-readable version of this information is available at /.well-known/security.txt (RFC 9116).

What we commit to

  • Acknowledgement within three working days
  • A dedicated contact and regular status updates
  • Remediation of confirmed vulnerabilities as quickly as possible, usually within 90 days
  • Public credit on request once the vulnerability is fixed
  • No legal action against security researchers who follow this policy

Rules for security researchers

  • Test only as far as necessary to demonstrate the vulnerability. Do not access third-party data, do not modify or delete anything.
  • No denial-of-service attacks, no spam, no social engineering against our staff, no physical attacks.
  • Give us time to fix the issue before publishing details – we agree on the timing together.
  • Treat any data obtained incidentally as confidential and delete it after reporting.

Out of scope

  • Output of automated scanners without demonstrated impact
  • Missing security headers without a concrete attack scenario, clickjacking on pages without sensitive actions
  • Version disclosure and best-practice deviations without exploitability
  • Vulnerabilities at our hosting provider – we are happy to forward these

Rewards

We do not run a bug bounty programme. For reproducible, previously unknown vulnerabilities we say thank you – and credit you as the finder on request.

PGP key