top of page

Bliggit Security

Deutsch

Sicherheitslücken melden

Sollten Sie eine Sicherheitslücke in unseren Produkten, darunter fallen

 

● die mobile App „bliggit“ und darauf basierende WhiteLabel-Apps

● das Partner-Portal

● unsere Web-Angeboten

 

feststellen, bitten wir Sie, uns diese verantwortungsvoll mitzuteilen.

 

Kontakt: security@bliggit.de

 

Erforderliche Angaben:

 

● Eine Beschreibung der Schwachstelle und der betroffenen Komponente

● Schritte zur Reproduktion, sofern möglich

● Optional: Ihre Kontaktdaten für Rückfragen (anonyme Meldungen sind ebenfalls möglich)

 

Unsere Zusagen:

 

● Empfangsbestätigung innerhalb von 3 Werktagen

● Erste Einschätzung der Gültigkeit und des Schweregrads innerhalb von 10 Werktagen

● Status-Updates mindestens alle 30 Tage während der Bearbeitung

● Übliches Offenlegungsfenster: 90 Tage ab Empfangsbestätigung, oder früher bei Verfügbarkeit einer Behebung

 

Safe-Harbour-Zusage: Gegen Personen, die in gutem Glauben handeln, uns eine angemessene Frist zur Behebung der gemeldeten Schwachstelle einräumen und dabei weder Daten Dritter über das zur Nachweisführung erforderliche Minimum hinaus einsehen oder verändern noch unseren Betrieb beeinträchtigen noch vor Ablauf der vereinbarten Frist Informationen öffentlich preisgeben, werden wir keine rechtlichen Schritte einleiten.

 

Wir betreiben derzeit kein kostenpflichtiges Bug-Bounty-Programm. Dies berührt die vorstehende Safe-Harbour-Zusage nicht.

 

Eine öffentliche Nennung als Melder erfolgt ausschließlich auf ausdrücklichen Wunsch. In allen übrigen Fällen werden die übermittelten Daten ausschließlich intern und im Rahmen der Bearbeitung des Meldefalls verwendet.

English

Reporting a security vulnerability

Should you discover a security vulnerability in any of our products, which include

 

● the "bliggit" mobile app and white-label apps based on it

● the Partner Portal

● our web services

 

we request that you report it to us responsibly.

 

Contact: security@bliggit.de

 

Required information:

 

● A description of the vulnerability and the affected component

● Steps to reproduce the issue, where possible

● Optional: your contact details for follow-up, should you wish to provide them (anonymous reports are also accepted)

 

Our commitments:

 

● Acknowledgement of receipt within 3 business days

● An initial assessment of validity and severity within 10 business days

● Status updates at least every 30 days during remediation

● Standard disclosure window: 90 days from acknowledgement, or sooner once a remedy becomes available

 

Safe harbour: We will not pursue legal action against any person who acts in good faith, affords us a reasonable period to remediate the reported vulnerability, and, in doing so, neither accesses nor modifies data belonging to third parties beyond what is strictly necessary to demonstrate the issue, nor impairs the operation of our services, nor discloses information publicly prior to the expiry of the agreed disclosure period.

 

We do not currently operate a paid bug bounty programme. This does not affect the safe harbour commitment set out above.

 

Reporters are credited publicly only at their explicit request; in all other cases, information provided is used exclusively for internal purposes in connection with the handling of the report.

bottom of page