Report a vulnerability
Security is our core business – so we take vulnerability reports seriously. If you have discovered a security issue on this website or in a service operated by us, we would like to hear from you.
How to reach us
Write toinfo@amanit.gmbh– in English or German. Helpful details include: the affected URL or service, a short description of the vulnerability, steps to reproduce and – if available – a proof of concept. The machine-readable version of this information is available at/.well-known/security.txt(RFC 9116).
What you can expect from us
- We aim to acknowledge your report within 5 business days.
- Where possible, we keep you informed about the fix.
- We expressly welcome reports made in good faith within the ground rules below – we do not intend to pursue legal action against such security research.
- If you wish, we credit you as the finder once the issue is fixed – or treat your report confidentially.
Ground rules
- Go only as far as necessary to demonstrate the vulnerability.
- Do not access third-party data, and do not modify or delete any data.
- No availability attacks (DoS), no spam, no social engineering, no physical access.
- Give us reasonable time to fix the issue – typically 90 days – before publishing details (coordinated disclosure).
Scope
This policy applies to this website and to services operated by amanIT GmbH. Please report vulnerabilities in third-party services (e.g. Cloudflare or Cal.com) directly to the respective provider.
Legal note
This policy is a voluntary, non-binding statement of intent. It does not create any legal claims or entitlements – in particular no right to a response, feedback or reward (no bug bounty programme) – and may be amended or withdrawn at any time. Statutory rights and obligations remain unaffected.
Last updated: August 2026