Skip to content

Report a vulnerability

Security is our core business – so we take vulnerability reports seriously. If you have discovered a security issue on this website or in a service operated by us, we would like to hear from you.

How to reach us

Write toinfo@amanit.gmbh– in English or German. Helpful details include: the affected URL or service, a short description of the vulnerability, steps to reproduce and – if available – a proof of concept. The machine-readable version of this information is available at/.well-known/security.txt(RFC 9116).

What you can expect from us

  • We aim to acknowledge your report within 5 business days.
  • Where possible, we keep you informed about the fix.
  • We expressly welcome reports made in good faith within the ground rules below – we do not intend to pursue legal action against such security research.
  • If you wish, we credit you as the finder once the issue is fixed – or treat your report confidentially.

Ground rules

  • Go only as far as necessary to demonstrate the vulnerability.
  • Do not access third-party data, and do not modify or delete any data.
  • No availability attacks (DoS), no spam, no social engineering, no physical access.
  • Give us reasonable time to fix the issue – typically 90 days – before publishing details (coordinated disclosure).

Scope

This policy applies to this website and to services operated by amanIT GmbH. Please report vulnerabilities in third-party services (e.g. Cloudflare or Cal.com) directly to the respective provider.

Legal note

This policy is a voluntary, non-binding statement of intent. It does not create any legal claims or entitlements – in particular no right to a response, feedback or reward (no bug bounty programme) – and may be amended or withdrawn at any time. Statutory rights and obligations remain unaffected.

Last updated: August 2026