# BFSGuard Security Policy # Verantwortliche Offenlegung von Sicherheitslücken # Responsible Disclosure of Security Vulnerabilities Contact: mailto:info@bfsguard.de Expires: 2027-04-20T23:59:59.000Z Preferred-Languages: de, en, tr Canonical: https://bfsguard.de/.well-known/security.txt Policy: https://bfsguard.de/security Acknowledgments: https://bfsguard.de/security # Scope: # - bfsguard.de (Website, API) # - app.bfsguard.de (Dashboard) # - widget.js (Customer-side embed script) # # Out of scope: # - Customer websites (contact customer directly) # - Third-party services (Payment-/Infra-/SMTP-Provider, siehe Datenschutz) # # Response SLA: 48 Stunden für Erstreaktion auf qualifizierte Meldungen. # Critical findings (RCE, authentication bypass, PII leak): Anerkennung in Hall of Fame möglich. # # Bitte keine automatisierten Scans/Last-Tests ohne Absprache — Rate-Limits blockieren. # No automated scans or load tests without prior authorization — rate-limits will block.