ILLUMENTIS.
DE

Vulnerability Disclosure Policy

How to responsibly report a security vulnerability in Illumentis — and what we commit to in return.

As of: September 29, 2026 Scope: Illumentis Beta (beta.illumentis.de) and its supporting infrastructure See also: Security & Transparency

Short version: if you find and report a security vulnerability in good faith, without accessing more data than necessary to confirm it, and without disrupting operations, you have nothing to worry about — quite the opposite, we're grateful.

1 Scope

In scope

The Illumentis beta application at beta.illumentis.de (API and frontend), as well as the static sites illumentis.de, illumentis.net, and bluegreen-solutions.de.

Out of scope

Denial-of-service attacks or anything that could disrupt the service for other users; high-rate automated mass scanning; social engineering against the developer or third parties; physical access to infrastructure; attacks against accounts that are not your own (no access to other users' data beyond the minimum needed to confirm the issue); vulnerabilities in third-party services we do not operate ourselves.

2 Safe Harbor Commitment

Anyone who reports a vulnerability in good faith, without accessing data beyond the minimum necessary to confirm it, and without disrupting operations, need not fear legal consequences. This applies regardless of whether the report is made through the contact channel below or through another responsible channel.

Concretely: we will not pursue criminal or civil legal action against you for good-faith testing conducted under this policy, and we will not refer you to law enforcement — as long as you stay within the scope described above.

3 How to Report

Contact

Email security@illumentis.net. German or English is fine.

What helps us respond quickly

A short description of the vulnerability, the affected component/URL, steps to reproduce, and — if you have one — your assessment of the impact (e.g. data access, privilege escalation). No proof-of-concept code beyond the minimum needed for confirmation is required.

4 What You Can Expect From Us

Acknowledgment

Typically within 5 business days.

Initial assessment

Typically within 10 business days — whether and how critical the reported issue is, and a rough estimate of when a fix can be expected.

Honest communication

Illumentis is currently built by a solo developer (see Security & Transparency) — the timelines above are honest targets, not a contractually guaranteed SLA. If we run behind, we will still reach out rather than go silent.

Recognition, not a bug bounty

There is currently no monetary reward program. With your consent, we are happy to publicly credit you as the finder once the issue is fixed.

Why we do it this way

A contact channel alone is usually not enough for the security research community — without an explicit assurance that a good-faith, responsible report will not be met with legal action, many researchers would rather not report a vulnerability at all, or report it anonymously/publicly instead of directly. This page is the long-form version of the commitment that also appears in our security.txt.