Security Policy

RESPONSIBILITY | TRANSPARENCY |
SECURITY | TRUST

Security
Working together for more safet

Vulnerability reporting
Please report potential security vulnerabilities exclusively
by e-mail:![]()
![]()
OpenPGP Public Key:
https://www.3esolutions.de/.well-known/pgp-key.asc
Fingerprint:
53E7 7101 70F7 6A40 E447
9365 668B 5F0B 6546 7D00
Please provide as much detailed information as possible so that we can efficiently analyze and evaluate your report.

Helpful information for your report
✔ Helpful information for your report
✔ Description of the vulnerability
✔ Affected URL, application, or system component
✔ Steps to reproduce
✔ Assessment of possible effects
✔ Proof of Concept (PoC), sofern vorhanden
✔ Date of determination
✔ Contact details for enquiries

Code of conduct for security researcher
We ask all whistleblowers and security researchers to adhere to the following principles:
✔ No access to personal data
✔ No copying, storing, or publishing of data
✔ No alteration, manipulation or deletion of information
✔ No impairment of the availability of systems or services
✔ No denial-of-service (DoS/DDoS) testing
✔ No social engineering attacks
✔ No automated, high-load attacks Compliance with all applicable
regulatory requirements

Our handling of reports
Nach Eingang einer Meldung werden wir:
✔ Confirm receipt promptly
✔ Analyze and evaluate the information
✔ Aassess the criticality of the reported vulnerability
✔ initiate necessary measures to minimize risk
✔ Contact us in case of queries
✔ Communicate the processing progress appropriately
Please understand that due to individual examinations, no fixed deadlines for processing can be guaranteed.

Responsible Disclosure
Please do not publish information about a vulnerability publicly until sufficient time has been given for analysis and correction or a joint vote has been taken.
A collaborative disclosure process can reduce potential risks for customers, partners and other stakeholders.

Safe Harbor
If security investigations are carried out in good faith, serve exclusively to identify vulnerabilities and do not impair the availability, integrity or confidentiality of our systems, 3e Solutions GmbH will process reports responsibly and support constructive cooperation.
This statement does not constitute a waiver of statutory rights and does not replace a legal assessment of the individual case.

Scope of application
This guideline applies to publicly accessible systems and services of 3e Solutions GmbH, in particular:
✔ www.3esolutions.de
✔ Public websites and web applications
✔ Publicly accessible services and interfaces
✔ information systems with Internet access operated
by 3e Solutions GmbH.
It does not include third-party systems, external platforms or services
of technology partners, unless they are operated directly by
3e Solutions GmbH.

Information Security at 3e Solutions
Information security is an essential part of the business processes of 3e Solutions GmbH.
As an ISO 27001-certified company, we pursue the goal of sustainably protecting the confidentiality, integrity and availability of information through technical, organizational and continuously developed security measures.
Responsibly reported vulnerabilities make a valuable contribution to this.


Security is a shared process
Thank you for your support!
