Vulnerability Reporting
We take reports of vulnerabilities in our publicly accessible systems seriously and welcome reports from outside the
company.
Contact
Email: security@attempto.eu
Phone: +49 89 2170377-0 (for urgent cases)
You may report in German or English, and you do not have to give us your name.
Scope
For technical vulnerabilities, this page covers the attempto.eu website and other publicly accessible services of
attempto GmbH & Co. KG. Systems operated by our customers are not covered, including those we work on. Please
report findings about those systems directly to the organisation operating them.
Other security-relevant observations
You can use the same contact channels for any other observation that may affect security, for example:
- Behaviour of attempto employees that puts the security of information at risk.
-
Observations about the physical security of our offices, such as unauthorised access, break-ins, theft or a found
attempto device.
- Attacks on our IT systems, misuse of attempto addresses or attempto credentials found in public.
- Incidents at suppliers or business partners that may affect the security of attempto.
We assess every report and hand it over to our internal security incident process.
What we ask of you
If you are investigating a technical vulnerability, we ask you to observe the following:
-
Describe the vulnerability so that we can reproduce it (affected URL or component, the steps you took and, if
possible, when).
- Limit your testing to what is necessary and use only your own test data.
-
Do not access data belonging to others, do not modify or delete any data, and do not disrupt operations (no load
testing, no denial-of-service attempts, no social engineering, no physical access).
- Give us time to fix the issue before you publish any details.
What you can expect from us
- We confirm that we received your report and get back to you with the result of our assessment.
- We treat your report and your data as confidential.
We do not pay rewards and do not run a bug bounty programme.
For information on how we process your personal data, please see our
privacy policy.