security
Responsible disclosure

Help us keep our services secure. Report vulnerabilities responsibly, give us time to resolve them, and receive recognition for your contribution.

Submit a report

approach
Our approach

Security is a shared responsibility. We value researchers and users who alert us to vulnerabilities so we can fix them before they are exploited. We strive for transparency within the boundaries of responsible disclosure.

Report immediately

Send your report to disclosure@econnect.eu as soon as you find something; do not share anything publicly before we have resolved it.

Give us time

We confirm your report within 5 business days and aim for a resolution within 90 days, depending on complexity.

No harm

Do not test denial-of-service attacks, social engineering, or use automated tools that disrupt the service.

Recognition

We acknowledge researchers in our hall of fame, unless you prefer to remain anonymous.

ground rules
What we expect from each other

Responsible disclosure works best when both parties adhere to a set of ground rules.

Frequently asked questions
What is out of scope?

Vulnerabilities in third-party services we do not manage, social engineering, physical attacks, and denial-of-service are out of scope.

Will I receive a reward?

We do not operate a fixed bug bounty, but we acknowledge researchers and provide appropriate recognition for high-impact findings.

How do I encrypt my report?

You can request our PGP key via disclosure@econnect.eu to send sensitive reports encrypted.

Found something?

Send your report to disclosure@econnect.eu. We confirm within 5 business days.

Submit a report

Other questions