Security
Responsible Disclosure
We welcome good-faith reports of suspected security vulnerabilities affecting the public DataSchutz website.
Last updated: 26 July 2026
How to report
Send an initial report to info@dataschutz.net with the subject “Responsible disclosure report”. Include the affected page or asset, steps to reproduce, potential impact and any supporting evidence that can be shared safely.
Good-faith research
Limit activity to what is necessary to confirm and describe the suspected issue. Stop if you encounter personal data, confidential information, credentials or access to systems beyond the minimum needed to demonstrate the concern.
A report does not create permission to test third-party systems, customer environments, payment infrastructure or any asset not clearly controlled by DataSchutz.
Activities that are not permitted
- Destructive testing, data deletion or alteration.
- Privacy violations or collection of personal information.
- Social engineering, phishing or impersonation.
- Denial-of-service, traffic flooding or resource exhaustion.
- Physical attacks or attempts to access offices or devices.
- Access beyond the minimum necessary to demonstrate the suspected issue.
- Public disclosure before DataSchutz has had a reasonable opportunity to investigate and respond.
What to expect
We aim to acknowledge useful reports and assess the information provided. Response and remediation timing depends on severity, reproducibility, scope and third-party dependencies.
DataSchutz does not currently promise financial rewards or operate a public bug-bounty programme. Please do not make payment a condition of reporting a vulnerability.