Coordinated vulnerability disclosure
Coordinated Vulnerability Disclosure / VDP for Password Depot
Purpose of this policy
AceBIT GmbH welcomes reports of vulnerabilities in Password Depot and related product web services for which AceBIT is responsible. This policy describes how security researchers can report potential vulnerabilities, which rules apply to security research, and what commitments AceBIT makes as part of coordinated disclosure.
Reports may be submitted in German or English.
Scope
- Password Depot Enterprise Server
- Password Depot Windows Client
- Password Depot macOS Client
- Password Depot Linux Client
- Browser Extension (Chrome, Edge, Firefox)
- Mobile apps (iOS, Android)
- Product-related web services on password-depot.de
Including third-party components insofar as they are part of the listed products.
Not covered
- Production customer environments, customer-specific installations, and other third-party systems
- Third-party operated services or infrastructures that are not part of Password Depot
- Social engineering, phishing, physical attacks, spam, brute force, credential stuffing, mass scanning, or denial-of-service testing
Safe Harbor
If you act in good faith, comply with this policy, limit your testing to the scope described above, and do not access, modify, delete, exfiltrate, or otherwise compromise data or impair services, we will–where legally permissible–not pursue civil claims in connection with such security research.
To the extent this is within our control and legally permissible, we will also not file a criminal complaint in connection with such security research.
This does not apply to actions outside the defined scope, to testing against customer or other third-party systems, to data protection violations, service disruptions, or other violations of applicable law.
Our expectations for security researchers
Encrypted communication
For sensitive technical details, please use the public PGP key of the Password Depot Security Team. Verify the fingerprint of the downloaded key before encrypting.
Also discoverable via RFC 9116 (security.txt) at /.well-known/security.txt.
How to report a vulnerability
Submit report
Please send your report to:
security@password-depot.dePlease include the following
- Affected product, version, build, and component
- Description of the vulnerability
- Steps to reproduce / Proof of Concept
- Assessment of impact and severity
- Test environment, configuration, and prerequisites
- Contact details and, if applicable, whether you would like to be credited by name
Confidentiality
We will treat your report and–if you wish–your identity confidentially, to the extent permitted by law. We will only publish your name with your prior consent.
Your information will only be shared to the extent necessary to review, remediate, and coordinate disclosure of the vulnerability or to comply with legal obligations.
What happens after you submit your report
Coordinated disclosure and Security Advisories
As soon as a security update or another effective remediation measure is available, we generally publish a Security Advisory for confirmed vulnerabilities.
If immediate publication would jeopardize the security of our users, we may delay publication until an appropriate time.
A Security Advisory contains at least
- A description of the vulnerability
- The affected products and versions
- Impact and severity
- Clear guidance for remediation or mitigation
Note on statutory reporting obligations
If a report indicates an actively exploited vulnerability or a serious security incident, we may be legally required to provide the necessary technical information to the competent authorities, the responsible CSIRT, and ENISA, and to inform affected users.
We will only disclose your identity to the extent legally required.
Recognition
We do not currently offer financial rewards or bug bounty payments unless this is expressly announced separately.
If you wish, we will acknowledge you in a Security Advisory or in an acknowledgment after the vulnerability has been resolved. Please let us know when submitting your report.