Security
Reporting Security Vulnerabilities
We take the security of groupios Mare Cloud seriously and are grateful for reports from security researchers. This page describes how to report a suspected security vulnerability to us. A machine-readable version for automated tooling is also available at /.well-known/security.txt.
What to report
Technical vulnerabilities in groupios Mare Cloud or its related systems - for example authentication flaws, unauthorized access to data, or vulnerabilities that could allow customer data to be compromised.
How to report
Email us at isms [at] step3it [dot] de with as precise a description of the vulnerability as possible, the steps to reproduce it, and, if applicable, the affected URLs or system components.
What you can expect from us
We acknowledge receipt of your report within 3 business days and keep you updated on progress until the vulnerability is resolved. Please do not publish details of a reported vulnerability before we have had the chance to fix it (coordinated disclosure, also known as responsible disclosure).
Safe Harbor
As long as you comply with this policy, limit your actions to what is necessary to report the issue, and avoid violating the privacy of third parties, disrupting live operations, or destroying data, we will not pursue legal action based on your report.