NET-LINE GmbH values the work of security researchers and the broader security community. If you believe you have discovered a security vulnerability in one of our systems, we encourage you to report it to us responsibly so that we can investigate and address the issue.
We are committed to maintaining the security and integrity of our services and appreciate responsible disclosure.
If you discover a potential security vulnerability, please report it to:
Please include as much detail as possible to help us reproduce and evaluate the issue, such as:
We will acknowledge receipt of your report as soon as possible.
When conducting security research on our systems, please adhere to the following guidelines:
This policy applies to public websites, APIs, applications, and infrastructure operated by NET-LINE Online-Dienste GmbH when the affected host publishes a /.well-known/security.txt file that links to this policy. This includes NET-LINE-operated services across our company and product domains.
Please identify the exact affected hostname, endpoint, and product in your report. A security.txt file applies only to the host from which it was retrieved; it does not automatically place unrelated third-party services or an entire parent domain in scope.
Third-party services and infrastructure providers are not in scope and should be reported directly to the respective provider.
If you act in good faith, test only in-scope systems, and follow this policy, NET-LINE Online-Dienste GmbH will not pursue legal action against you for that security research. This policy does not authorize disruptive testing, access to data belonging to others, or testing of third-party systems.
NET-LINE GmbH does not operate a public bug bounty program.
While we appreciate security reports and may acknowledge significant findings at our discretion, financial rewards are not guaranteed.
When you report a vulnerability responsibly, we will:
We request that you do not publicly disclose a vulnerability until we have had a reasonable opportunity to investigate and address the issue.
Thank you for helping us keep our systems and users secure.