Security Policy

RESPONSIBILITY | TRANSPARENCY |
SECURITY | TRUST

Security

Working together for more safet

Vulnerability reporting

Please report potential security vulnerabilities exclusively
by e-mail:

 
OpenPGP Public Key:
https://www.3esolutions.de/.well-known/pgp-key.asc

Fingerprint:
53E7 7101 70F7 6A40 E447
9365 668B 5F0B 6546 7D00

Please provide as much detailed information as possible so that we can efficiently analyze and evaluate your report.

Helpful information for your report

✔ Helpful information for your report
✔ Description of the vulnerability
✔ Affected URL, application, or system component
✔ Steps to reproduce
✔ Assessment of possible effects
✔ Proof of Concept (PoC), sofern vorhanden
✔ Date of determination
✔ Contact details for enquiries

Code of conduct for security researcher

We ask all whistleblowers and security researchers to adhere to the following principles:

✔ No access to personal data
✔ No copying, storing, or publishing of data
✔ No alteration, manipulation or deletion of information
✔ No impairment of the availability of systems or services
✔ No denial-of-service (DoS/DDoS) testing 
✔ No social engineering attacks
✔ No automated, high-load attacks Compliance with all applicable
   regulatory requirements

Our handling of reports

Nach Eingang einer Meldung werden wir:

✔ Confirm receipt promptly
✔ Analyze and evaluate the information
✔ Aassess the criticality of the reported vulnerability
✔ initiate necessary measures to minimize risk
✔ Contact us in case of queries
✔ Communicate the processing progress appropriately

Please understand that due to individual examinations, no fixed deadlines for processing can be guaranteed.

Responsible Disclosure

Please do not publish information about a vulnerability publicly until sufficient time has been given for analysis and correction or a joint vote has been taken.

A collaborative disclosure process can reduce potential risks for customers, partners and other stakeholders.

Safe Harbor

If security investigations are carried out in good faith, serve exclusively to identify vulnerabilities and do not impair the availability, integrity or confidentiality of our systems, 3e Solutions GmbH will process reports responsibly and support constructive cooperation.

This statement does not constitute a waiver of statutory rights and does not replace a legal assessment of the individual case.

Scope of application

This guideline applies to publicly accessible systems and services of 3e Solutions GmbH, in particular:

✔ www.3esolutions.de
✔ Public websites and web applications
✔ Publicly accessible services and interfaces
✔ information systems with Internet access operated
   by 3e Solutions GmbH.

It does not include third-party systems, external platforms or services
of technology partners, unless they are operated directly by
3e Solutions GmbH.

Information Security at 3e Solutions

Information security is an essential part of the business processes of 3e Solutions GmbH.

As an ISO 27001-certified company, we pursue the goal of sustainably protecting the confidentiality, integrity and availability of information through technical, organizational and continuously developed security measures.

Responsibly reported vulnerabilities make a valuable contribution to this.

Security is a shared process

Thank you for your support!