Report a Security Issue

Protecting our customers' data is our top priority. Security isn't an afterthought — it's built into our architecture, operations, and development process. If you find a vulnerability, help us fix it quickly.

This covers anything that could compromise user data or impact the service, including phishing attempts targeting Startup Business Cockpit or our users. The sooner we know, the faster we can act.

How we handle reports

We will not take legal action against anyone who responsibly reports vulnerabilities. As long as you act in good faith, don't access other people's data, and give us time to fix the issue, you're safe.

We acknowledge receipt of your report within 48 hours and keep you informed about progress. Every report is treated confidentially and stored only as long as necessary for resolution or as required by law.

We do not operate a bug bounty program and do not pay rewards for reports. However, we appreciate every responsible disclosure and handle all reports carefully.

What we need from you

Our disclosure policy covers:

  • app.startup-business-cockpit.de (application)
  • startup-business-cockpit.de (website)
  • Associated APIs and infrastructure under these domains

Third-party services (e.g. hosting providers) are not in scope. If you're unsure, just ask.

To help us understand the issue quickly, please include:

  • Description of the issue
  • Affected URL or component
  • Timestamp and your timezone
  • Steps to reproduce or debug information
  • Contact information for follow-up questions

Contact

E-Mail: security@on-promise.cloud
Security.txt: security.txt

Frequently Asked Questions

Do you pay for reported vulnerabilities?
No. We do not operate a bug bounty program. We are grateful for every responsible disclosure and handle all reports carefully.
What happens after I submit a report?
We acknowledge receipt within 48 hours, investigate the issue, and keep you informed about progress. Once fixed, we'll let you know.
Can I report anonymously?
Yes. However, we recommend providing contact details so we can reach out with follow-up questions. Without contact information, we cannot provide status updates.
Which systems are covered?
Our policy covers app.startup-business-cockpit.de, startup-business-cockpit.de, and associated APIs. Third-party services like hosting providers are not in scope.