Vulnerability Disclosure Policy
Stand: 2026-08-18
Security vulnerabilities on the website or in programs of gaijin.at can be reported confidentially to web@gaijin.at.
Communication is exclusively via email in German or English. Generally, every incoming report will be answered within one week. No response will be provided if there is suspicion of an automated or AI-generated report.
Reports without a valid email address for follow-up questions may not be processed or may only be processed inadequately.
The report should include at least the following:- the URL or program in question
- a brief description of the vulnerability and its potential impact
- the exact steps for reproduction
- screenshots and/or text output
The following actions are not permitted:
- Use of automated scanning tools
- Attacks such as DoS/DDoS or brute-force attacks
- Use of malware such as viruses, Trojans, keyloggers, etc.
- Access to other users' data
- Modifying or deleting data on the server
- Exploiting a vulnerability beyond what is necessary for proof
- Publishing the vulnerability or the data obtained
No legal action will be taken against the person reporting a vulnerability, provided this policy is followed. This does not apply if there is or was obvious criminal intent.
No compensation will be provided for reported security vulnerabilities or other errors.