If you have found a security vulnerability in our software or on one of our websites: please tell us. This page explains how — and what you can expect from us in return.
How to report
Write to support@autenova.com. Privately, please — not as a public post in a forum, an issue tracker or on wordpress.org.
What helps is anything that saves us from having to reconstruct it:
- a description of the problem and what it can be used to do,
- the steps to reproduce it — a proof of concept if you have one,
- the version of the software and the environment you saw it in (for WordPress extensions: the program, WordPress and PHP versions).
A report in German or English is equally welcome.
What we commit to
- We answer. We acknowledge receipt within three business days — including when the assessment itself will take longer.
- We keep you posted until the matter is settled, and tell you what we are doing and when.
- We coordinate disclosure with you. If you want to publish your finding, we agree a date by which a fix can have reached users. We ask for that window; we do not ask for your silence.
- We credit you if you want to be credited — and do not, if you would rather we didn’t.
- We will not come after you. Anyone researching and reporting in good faith within the scope of this page has no legal action to fear from us. That holds even if the report turns out to be unfounded.
Scope
In scope is the code of our own software, this shop, and the services we operate.
Out of scope are third-party libraries we ship — please report those to their maintainers, but tell us as well so we can pull in a fixed version. Also out of scope: our customers’ systems and those of our service providers.
Reports that amount to a tool finding are of limited help — automated scans with no demonstrated impact, missing headers with no concrete attack path, notes about theoretically outdated versions. We do look at them, but they go to the back of the queue.
What we ask you not to do
- no denial-of-service attacks and no testing that disrupts operation,
- do not view, alter, copy or keep other people’s data — if you come across some by accident, stop and tell us,
- no social engineering against us, our customers or our service providers.
No bug bounty
We do not pay rewards. That is not a lack of appreciation but honesty about the size of this business — and the reason the commitments above are meant all the more seriously.
Machine-readable
The same details are available under RFC 9116 at /.well-known/security.txt.