Vulnerability Disclosure Policy

Coordinated vulnerability disclosure

Coordinated Vulnerability Disclosure / VDP for Password Depot

As of: March 10, 2026

Safe Harbor Scope 48h acknowledgment Coordinated Disclosure
Purpose & Scope

Purpose of this policy

AceBIT GmbH welcomes reports of vulnerabilities in Password Depot and related product web services for which AceBIT is responsible. This policy describes how security researchers can report potential vulnerabilities, which rules apply to security research, and what commitments AceBIT makes as part of coordinated disclosure.

Reports may be submitted in German or English.

Scope

  • Password Depot Enterprise Server
  • Password Depot Windows Client
  • Password Depot macOS Client
  • Password Depot Linux Client
  • Browser Extension (Chrome, Edge, Firefox)
  • Mobile apps (iOS, Android)
  • Product-related web services on password-depot.de

Including third-party components insofar as they are part of the listed products.

Not covered

  • Production customer environments, customer-specific installations, and other third-party systems
  • Third-party operated services or infrastructures that are not part of Password Depot
  • Social engineering, phishing, physical attacks, spam, brute force, credential stuffing, mass scanning, or denial-of-service testing
Safe Harbor

Safe Harbor

If you act in good faith, comply with this policy, limit your testing to the scope described above, and do not access, modify, delete, exfiltrate, or otherwise compromise data or impair services, we will–where legally permissible–not pursue civil claims in connection with such security research.

To the extent this is within our control and legally permissible, we will also not file a criminal complaint in connection with such security research.

This does not apply to actions outside the defined scope, to testing against customer or other third-party systems, to data protection violations, service disruptions, or other violations of applicable law.

This policy does not authorize testing outside the scope described here.
Guidelines

Our expectations for security researchers

1 Act carefully and in good faith, and limit your testing to what is necessary to clearly demonstrate the vulnerability.
2 Do not access real customer data. If you unintentionally gain access to sensitive data, stop testing immediately and inform us without delay.
3 Do not modify, delete, exfiltrate, or disclose any data.
4 Do not perform any testing that could impair systems or services or reduce their availability.
5 Do not use social engineering, phishing, or physical attacks, and do not install backdoors or persistence mechanisms.
6 Do not share details publicly before we have jointly agreed on a coordinated disclosure date.
PGP key

Encrypted communication

For sensitive technical details, please use the public PGP key of the Password Depot Security Team. Verify the fingerprint of the downloaded key before encrypting.

Identity Password Depot Security <security@password-depot.de> Primary fingerprint (Ed25519, sign+certify) 29D3 2E66 D801 E549 8EFD C944 2D9D 5787 9104 EBAA Encryption subkey (Curve25519) 8FC8 9959 3ACD 6D36 4F81 CC19 18A4 0C54 0FD1 0767 Validity Primary key until 2031-04-23 · Encryption subkey until 2028-04-23 Key download https://www.password-depot.de/.well-known/pgp-key.asc

Also discoverable via RFC 9116 (security.txt) at /.well-known/security.txt.

Reporting

How to report a vulnerability

Submit report

Please send your report to:

security@password-depot.de

Please include the following

  • Affected product, version, build, and component
  • Description of the vulnerability
  • Steps to reproduce / Proof of Concept
  • Assessment of impact and severity
  • Test environment, configuration, and prerequisites
  • Contact details and, if applicable, whether you would like to be credited by name
Please do not send unnecessary personal data or large datasets from production environments.

Confidentiality

We will treat your report and–if you wish–your identity confidentially, to the extent permitted by law. We will only publish your name with your prior consent.

Your information will only be shared to the extent necessary to review, remediate, and coordinate disclosure of the vulnerability or to comply with legal obligations.

Process

What happens after you submit your report

Acknowledgement of receipt 48 hours We will confirm receipt of your report.
Initial assessment 7 days We will let you know whether we classify the report as valid, duplicate, out of scope, or currently not reproducible.
Ongoing updates every 30 days We will keep you informed about the status of processing until the issue is resolved or disclosure has been coordinated.
Disclosure

Coordinated disclosure and Security Advisories

As soon as a security update or another effective remediation measure is available, we generally publish a Security Advisory for confirmed vulnerabilities.

If immediate publication would jeopardize the security of our users, we may delay publication until an appropriate time.

A Security Advisory contains at least

  • A description of the vulnerability
  • The affected products and versions
  • Impact and severity
  • Clear guidance for remediation or mitigation

Note on statutory reporting obligations

If a report indicates an actively exploited vulnerability or a serious security incident, we may be legally required to provide the necessary technical information to the competent authorities, the responsible CSIRT, and ENISA, and to inform affected users.

We will only disclose your identity to the extent legally required.

Recognition

We do not currently offer financial rewards or bug bounty payments unless this is expressly announced separately.

If you wish, we will acknowledge you in a Security Advisory or in an acknowledgment after the vulnerability has been resolved. Please let us know when submitting your report.

AceBIT GmbH Schleiermacherstr. 10 · 64283 Darmstadt · Germany Email: security@password-depot.de
Report a vulnerability