How to responsibly report a security vulnerability in Illumentis — and what we commit to in return.
Short version: if you find and report a security vulnerability in good faith, without accessing more data than necessary to confirm it, and without disrupting operations, you have nothing to worry about — quite the opposite, we're grateful.
The Illumentis beta application at beta.illumentis.de (API and frontend), as well as the static sites illumentis.de, illumentis.net, and bluegreen-solutions.de.
Denial-of-service attacks or anything that could disrupt the service for other users; high-rate automated mass scanning; social engineering against the developer or third parties; physical access to infrastructure; attacks against accounts that are not your own (no access to other users' data beyond the minimum needed to confirm the issue); vulnerabilities in third-party services we do not operate ourselves.
Anyone who reports a vulnerability in good faith, without accessing data beyond the minimum necessary to confirm it, and without disrupting operations, need not fear legal consequences. This applies regardless of whether the report is made through the contact channel below or through another responsible channel.
Concretely: we will not pursue criminal or civil legal action against you for good-faith testing conducted under this policy, and we will not refer you to law enforcement — as long as you stay within the scope described above.
Email security@illumentis.net. German or English is fine.
A short description of the vulnerability, the affected component/URL, steps to reproduce, and — if you have one — your assessment of the impact (e.g. data access, privilege escalation). No proof-of-concept code beyond the minimum needed for confirmation is required.
Typically within 5 business days.
Typically within 10 business days — whether and how critical the reported issue is, and a rough estimate of when a fix can be expected.
Illumentis is currently built by a solo developer (see Security & Transparency) — the timelines above are honest targets, not a contractually guaranteed SLA. If we run behind, we will still reach out rather than go silent.
There is currently no monetary reward program. With your consent, we are happy to publicly credit you as the finder once the issue is fixed.
A contact channel alone is usually not enough for the security research community — without an explicit assurance that a good-faith, responsible report will not be met with legal action, many researchers would rather not report a vulnerability at all, or report it anonymously/publicly instead of directly. This page is the long-form version of the commitment that also appears in our security.txt.