Report a security vulnerability
If you have found a vulnerability in one of our systems, we would rather hear it from you than read about it in the press. This page tells you what we expect from a report, what legal risk you are taking, and what you get back from us.
Report here: reporting form. We deliberately do not publish a reporting address. An open address today is mainly a target for machine-generated bulk submissions, and those crowd out the reports that matter.
Legal commitment
German criminal law makes no exception for security research. § 202a StGB makes it an offence to obtain access to data not intended for you without authorisation and by circumventing an access safeguard. The fact that you only intended to report the flaw does not change the offence - your intent matters at the point where authorisation is assessed. That is exactly where we come in. A reform bill exists but has not been passed. Anyone who reports therefore carries a real risk, and we do not think they should carry it alone.
Our commitment: if you look for and report a vulnerability in good faith and within these rules, you will face no legal action from us. Gosign will file no criminal complaint and will not pursue civil claims against such reporters.
We authorise you in advance to access our systems and the data we store in them, to the extent necessary to establish and evidence a vulnerability. This authorisation constitutes consent within the meaning of §§ 202a and 202b StGB and - where a flaw cannot be evidenced without write access and you restore the original state without delay - within the meaning of §§ 303a and 303b StGB as well. It applies to acts from the publication date of this version onwards; we cannot grant it retroactively.
What we cannot do: prosecution is not in our hands. §§ 202a and 202b StGB are generally prosecuted only on complaint - and we waive that complaint - but the public prosecutor may act of their own motion where there is a particular public interest, and for § 202c StGB the complaint requirement does not apply at all. Our authorisation also reaches only as far as our own power of disposal: we cannot give consent over the personal data of our users and clients, and we cannot speak for third parties - our clients, affected individuals, our service providers.
If third parties or authorities ask us about your research, we will first confirm only that it took place under these rules. We will not disclose your identity on our own initiative. If we are required to say more, we will inform you beforehand where we are legally permitted to do so.
This commitment does not apply, to the extent that you
- copy, publish or pass on data belonging to others,
- modify or delete data, or impair the availability of systems,
- demand payment or any other consideration for your silence,
- or test systems outside the scope below - third-party systems in particular.
What is in scope
All services operated by Gosign under gosign.de, including its subdomains,
and our country domains (gosign.at, gosign.es,
gosign.pl, gosign.pt, gosign.fi,
gosign.io, gosign.it, gosign.se,
gosign.pk).
Out of scope are the accounts and systems of our service providers (hosting, CDN, mail, model providers) and the sites we operate for clients - for those, see "If your report concerns a client site" below.
AI system findings
We build and operate AI agent infrastructure. Conventional disclosure processes do not cover the failure classes this produces, so we name them as a category of their own:
- Prompt injection - injected instructions that make a model take an action the operator did not intend.
- Tool misuse - a model uses a tool available to it outside its intended purpose.
- Data leakage through model context - content reaches recipients through a model's context who should not see it.
- Personal data in model output - a model emits personal data it must not emit.
Where we draw the line: a factually wrong or undesirable model output with no security effect is not a vulnerability. A model that can be talked into a rude answer is a quality issue; a model that can be talked into emitting someone else's data is worth reporting.
What is not covered
Our commitment does not cover the following, and we expressly ask you not to do them:
- denial-of-service and load testing of any kind (overload is not evidence), and likewise high request rates below that threshold,
- social engineering, meaning the deception of staff, clients or suppliers, including phishing,
- physical access to premises, devices or storage media,
- attacks on third-party accounts, and testing against third-party services we use (hosting, CDN, model providers),
- automated mass scanning without manual verification of your own,
- anything beyond what the evidence requires: created accounts, backdoors or scheduled jobs, privilege escalation, movement into further systems, changes to credentials or configuration, deleting or altering logs,
- testing against live payment or contract transactions,
- accessing more data than the evidence requires - one record proves a flaw as well as a thousand,
- contacting affected users on your own initiative.
We close reports without substantive review where they visibly consist of raw scanner or model output and carry no verification of your own.
If you came across personal data
This is the case where we need your help most. If you accessed personal data during testing:
- stop testing immediately,
- delete all copies,
- confirm the deletion in your report,
- and state the scope and period of the access.
Where the finding concerns our own systems, we assess it as a personal data breach and report it to the competent supervisory authority without undue delay and at the latest within 72 hours where there is a risk to individuals (Art. 33 GDPR); where the risk is high, we also notify the individuals concerned (Art. 34 GDPR). Where the finding concerns a client site, the client reports as controller - we report to them without delay. Your details on scope and period inform that assessment; they change nothing about the commitment above.
Deadlines
We separate two things that often get conflated - the confirmation that your report arrived, and the first substantive assessment by a human being:
- Immediately, on screen: your case number appears after you submit. We do not send a confirmation email - please note the number down, it cannot be recovered afterwards.
- Within five working days: a human being reviews your report. If you left a contact address, you receive a first assessment within that period - including when we close your report, and why. Without an address we cannot reach you; the review still happens. The period starts when a report arrives with all mandatory fields of the form completed; working days are Monday to Friday excluding public holidays in Hamburg.
If your report describes access to personal data or an ongoing exploitation, we look at it with priority - outside business hours as well. Please flag it in the first sentence of the "Impact" field. We do not commit to a fixed number of hours for this today; we would rather promise nothing than name a deadline nobody is on call for.
We do not commit to a deadline for assessment or remediation. A remediation promise would be a promise about things that, with complex findings, are not ours alone to control.
Publication
We ask you to publish your finding once it has been fixed - but no later than 90 days after your report, even if we have not finished by then. Publishing after that period does not breach these rules and does not cost you the commitment above. If we need longer, we will tell you why and ask for an extension; the decision is yours. Personal data of third parties belongs in no publication.
You may contact the German BSI at any time, anonymously if you prefer; under § 5 BSIG it is the national coordinator for coordinated vulnerability disclosure. Nothing on this page restricts your right to involve an authority or to lodge a complaint with a data protection supervisory authority.
If your report concerns a client site
For the operation of a client site we act as processor; the client is the controller and decides on remediation. That is not a mere formality - it determines what we can commit to.
We cannot give the commitment above for a client site in our own right.
We have no power of disposal over our clients' systems and data, and we cannot waive
their rights. Where a client has assigned that commitment to us in writing, it appears
in the security.txt of the site in question, names the client, and then
applies there too. Absent such a statement, we accept your report, pass it on and
advocate for you with the operator - we cannot commit to more for that system.
- We pass your report to the operator without undue delay - where there are indications of access to personal data, with no intermediate step; otherwise as set out in the relevant data processing agreement, which may specify shorter periods. Their statutory deadline starts with their knowledge, and we must not delay it.
- If the operator does not respond, we point out the risk to them in writing and keep you informed.
What you get back
We pay no bounties. What we offer:
- a case number you can rely on in dealings with us,
- a first assessment within five working days, if you make yourself reachable,
- and, if you wish, credit by name once the finding is fixed - anonymous if you prefer.
On credit: we name the name or pseudonym you give us, and only you - not third parties. If you want a team credited, we need individual consent from every person named. We credit no one before remediation. You may withdraw your consent at any time, informally (web26 [at] gosign.de); we then remove the entry. The lawfulness of processing carried out until then remains unaffected. We will set up a public credits page once the first credit is due.
And the commitment above, in writing.
What happens to your report
For this reporting channel Gosign is the controller under the GDPR - including where your report concerns a client site. We store the details you enter in the form, your contact address if you leave one, a salted hash of your IP address and an equally salted hash of its network range; we do not store the address itself. The legal basis is our legitimate interest in the security of our systems and those of our clients (Art. 6(1)(f) GDPR), and for the credit your consent (Art. 6(1)(a)). Without a contact address your report is anonymous - we then store nothing that identifies you.
Details on recipients, retention and your rights are in the "Security Vulnerability Reporting" section of our privacy policy. Questions go to web26 [at] gosign.de.
We deliberately do not publish a PGP key: a key nobody reliably attends to is worse than none. The form is transmitted over TLS. If you have evidence you would rather not send unencrypted, say so in the report and we will agree a route with you.
This version: 19 August 2026.