Coordinated Vulnerability Disclosure Policy

Report vulnerabilities responsibly. We assess every report carefully, keep you informed and coordinate disclosure with you.

Expectations for reporters

Please ensure that your research remains proportionate. You do not need to demonstrate that a large-scale attack could affect our systems, alter large amounts of data or access systems deeply.

If you want to demonstrate a vulnerability, please observe the following guidance:

Guidance for your research

  • Access only the data necessary to demonstrate the vulnerability.
  • If data manipulation is possible, a proof of concept using non-critical content is sufficient. Do not exploit the vulnerability; we take all vulnerability reports seriously and handle them with care.
  • For database access, evidence of the existing tables is sufficient. You do not need to disclose all database contents.
  • Do not use or retain personal data.

Scope

This scope describes which systems and activities are covered by this policy. Please keep your research within this framework.

In scope

  • IFD GmbH products and services.

Out of scope

  • Social engineering, phishing and attacks against employees or customers.
  • Third-party systems and services not operated by IFD GmbH.

Our commitment

Fair treatment

If you act within this policy, keep information confidential and avoid unnecessary harm, you need not fear civil or criminal consequences.

Recognition

If you wish, we will name you in the published security advisory. You can of course remain anonymous on request.

Possible reward

For reports of previously unknown vulnerabilities, we may grant a reward depending on the severity and quality of your report.

If you identify a vulnerability in a third-party component with an official bug-bounty program, submit any reward claim yourself. We make no claim to it.

Report a vulnerability

To help us understand, assess and reproduce the vulnerability, your report should contain the same details as our contact form. Required details let us act; optional details speed up our assessment:

What to include in your report

  • RequiredA detailed description of the vulnerability.
  • RequiredThe affected product, application or component.
  • RequiredThe expected impact of exploitation, for example on availability, integrity or confidentiality.
  • RequiredWhether the vulnerability is already publicly known.
  • RequiredAn email address for follow-up questions.
  • OptionalThe version number of the affected component.
  • OptionalThe runtime environment or project name.
  • OptionalSteps to reproduce the issue.
  • OptionalThe potential exploitation path.
  • OptionalA minimal proof of concept, such as code, a screenshot or a description.
You may also report anonymously by omitting your name and email address. However, anonymous reports can only be handled to a limited extent because we cannot ask follow-up questions.
Confidentiality matters to us. Do not share your findings with third parties while the vulnerability remains unresolved. After the process is complete, please delete all sensitive information obtained during your research.
Please submit your report in German or English so we can process it quickly and without translation.
Report vulnerability

How we handle reports

We work with you transparently and responsibly throughout the process.

Acknowledgement within three business days

You will receive a confirmation after we receive your report. Within three business days, we will share our initial assessment and the expected handling time.

Assessment and remediation

We keep you informed about progress. The handling time depends on severity, complexity and supply-chain dependencies.

Coordinated disclosure

The process is complete once the vulnerability has been assessed, remediated or effectively mitigated and a coordinated disclosure has taken place. We will agree the timing and scope with you in advance where possible.