Working Together for Greater Security: How to Report Vulnerabilities Correctly
The security of our systems and the protection of data are our top priorities. Despite our utmost care, errors can never be completely ruled out. If you have discovered a security vulnerability in our systems, we are very grateful for your assistance and for bringing it to our attention.
A structured approach helps us address the vulnerability as quickly and smoothly as possible. Please keep the following points in mind when submitting your report:
Direct Contact
Please send your findings via email to psirt@adiro.com.
OpenPGP fingerprint: 864BF460111E081E1D0884B2AFEB114137BDDBC7
Public key: https://www.adiro.com/.well-known/openpgp-key_psirt.asc
Language: German or English
Transmission: preferably encrypted
This email address is specifically set up for vulnerabilities in our own systems.
Precise location information
Please describe as specifically as possible where the vulnerability is located. Provide us with the exact URL, the affected IP address, the product, or other unique system identifiers.
The Error Pattern
Please describe in detail what happens when the vulnerability is triggered. What unexpected behavior does the system exhibit?
Step-by-Step Instructions
In order for our technicians to resolve the issue, we first need to reproduce it internally. Detailed instructions on how to reproduce the error step by step are the most important basis for this.
Context and Risk Assessment
While we are well aware of common attack vectors such as XSS and the risks they pose, some situations are more complex or less clear-cut. Please help us prioritize by briefly explaining why the bug is a problem in this specific context and what could happen in the worst-case scenario.
Proposed Solutions
If you already have an idea or specific suggestions on how we can resolve the issue, please feel free to share your proposed solutions with us directly.
Inquiries and Anonymity
If you have any questions, it would be very helpful for us if you could provide a way for us to contact you. However, we respect your desire for privacy and will also accept feedback completely anonymously upon request.
Thank you very much for your attention and your valuable contribution to our safety!