Collectu - Coordinated Vulnerability Disclosure Policy ===================================================== Collectu GmbH treats the security of its products and services as a product requirement. This policy describes how to report a vulnerability to us and what happens afterwards. It applies to all software and services operated by Collectu GmbH, including Collectu Hub (https://collectu.de) and Collectu Core. Reporting --------- Send reports to security@collectu.de. This address is the single point of contact for vulnerability reports for all Collectu products. Please do not open public issues for security problems, and please do not disclose the issue publicly before we have agreed a disclosure date with you. Where possible, include: - The affected product and version. - What the vulnerability allows an attacker to do. - Steps to reproduce, a proof of concept, or the configuration needed to trigger it. - How you would like to be credited, or that you prefer to stay anonymous. What we commit to ----------------- 1. Acknowledgement. We confirm receipt within 24 hours. 2. Assessment. We validate and rate the report, and keep you informed of the status. 3. Remediation. We develop, test and release a fix, and inform affected users. 4. Disclosure. We agree a disclosure date with you and publish a security advisory. We credit reporters in the advisory unless they ask us not to. Safe harbour ------------ We will not pursue or support legal action against anyone who reports a vulnerability in good faith under this policy, provided that you: - Only test against accounts and data you own or have explicit permission to test. - Do not access, modify, delete or exfiltrate other users' data. - Do not degrade, disrupt or overload our services - no denial-of-service, no spam, no automated scanning that materially affects availability. - Do not use social engineering, physical attacks, or attacks against our employees. - Give us reasonable time to remediate before disclosing. In scope -------- - The Collectu Hub api and web application. - Collectu Core and its official modules. - The infrastructure operated by Collectu under the domains above. Out of scope ------------ - Findings that only apply to a misconfigured deployment, where the secure configuration is documented (see the security documentation shipped with Collectu Core). - Community-contributed modules published by third parties on the Hub. Report those to us anyway - we will unpublish malicious modules - but they are not Collectu products. - Missing hardening headers, or results from automated scanners, without a demonstrated impact. - Denial of service through sheer volume of requests. Security updates and support period ----------------------------------- Security fixes are provided for the latest released version. The security support period is at least 5 years. Advisories are published together with the fix. Contact ------- Collectu GmbH, Seidenstraße 36, 70174 Stuttgart, Germany Security contact: security@collectu.de Website: https://collectu.de