Help us keep our services secure. Report vulnerabilities responsibly, give us time to resolve them, and receive recognition for your contribution.
Submit a report
Security is a shared responsibility. We value researchers and users who alert us to vulnerabilities so we can fix them before they are exploited. We strive for transparency within the boundaries of responsible disclosure.
Send your report to disclosure@econnect.eu as soon as you find something; do not share anything publicly before we have resolved it.
We confirm your report within 5 business days and aim for a resolution within 90 days, depending on complexity.
Do not test denial-of-service attacks, social engineering, or use automated tools that disrupt the service.
We acknowledge researchers in our hall of fame, unless you prefer to remain anonymous.
Responsible disclosure works best when both parties adhere to a set of ground rules.
Vulnerabilities in third-party services we do not manage, social engineering, physical attacks, and denial-of-service are out of scope.
We do not operate a fixed bug bounty, but we acknowledge researchers and provide appropriate recognition for high-impact findings.
You can request our PGP key via disclosure@econnect.eu to send sensitive reports encrypted.
Send your report to disclosure@econnect.eu. We confirm within 5 business days.
Submit a report
Other questions