Report a security vulnerability
If you have found a vulnerability in one of our systems, we want to hear it from you rather than read about it. This page tells you what we expect from a report, what legal risk you are taking, and what you get back from us.
Report here: reporting form. We deliberately do not publish a reporting address. An open address today is mainly a target for machine-generated bulk submissions, and those crowd out the reports that matter.
Legal commitment
German criminal law makes no exception for security research: § 202a StGB applies whenever someone obtains access to data not intended for them - even if the only intention was to report the flaw. A reform bill exists but is not in force. Anyone who reports therefore carries a real risk, and we do not think they should carry it alone.
Our commitment: if you look for and report a vulnerability in good faith and within these rules, you have nothing to fear from us. Gosign will file no criminal complaint and will not pursue civil claims against such reporters, and we consider your work authorised by us within the meaning of §§ 202a et seq. StGB. If third parties or authorities ask us about your research, we will tell them it took place under this policy.
This commitment does not apply where you
- copy, publish or pass on data belonging to others,
- modify or delete systems, or impair their availability,
- demand payment or any other consideration for your silence,
- or test systems not listed in this policy - third-party systems in particular.
What is in scope
All services operated by Gosign under gosign.de, plus the client sites we
operate, where their own security.txt points to this page.
AI system findings
We build and operate AI agent infrastructure. Conventional disclosure policies do not cover the failure classes that come with it, so we list them as a category of their own:
- Prompt injection - injected instructions that make a model take an action its operator did not intend.
- Tool misuse - a model using a tool available to it outside that tool's purpose.
- Data leaving through the model context - content reaching recipients who must not see it, by way of a model's context.
- Personal data in model output - a model emitting personal data it must not emit.
Where the line runs: a factually wrong or undesirable model output with no security effect is not a vulnerability. A model that can be talked into being rude is a quality issue; a model that can be talked into disclosing someone else's data is worth a report.
What is not covered
The commitment above does not extend to the following, and we ask you not to do them:
- denial-of-service and load testing of any kind (overload proves nothing),
- social engineering, meaning the deception of staff, customers or suppliers, including phishing,
- physical access to premises, devices or storage media,
- attacks on third-party accounts, and testing against third-party services we use (hosting, CDN, model providers),
- automated mass scans without your own manual verification.
Reports that visibly consist of raw scanner or model output, with no verification of your own, we close without substantive review.
If you saw data along the way
This is the case where we need your cooperation most. If you accessed personal data during testing:
- stop immediately,
- delete every copy,
- confirm the deletion in your report,
- and state the scope and period of the access.
We are obliged to assess such cases as a personal data breach and, where applicable, to notify the supervisory authority within 72 hours. Your information helps us do that and changes nothing about the commitment above.
Deadlines
We keep three things apart that are often conflated - confirming that your report arrived, a human's first assessment, and the legally bound hand-over in urgent cases:
- Immediately, automatically: you receive an acknowledgement with a case number the moment you submit.
- Within five working days: a human has reviewed your report and given you a first assessment. The clock starts when a complete report arrives; working days are Monday to Friday excluding public holidays in Hamburg.
- Within 24 hours: where your report indicates access to personal data, or describes active exploitation. That path bypasses every rate limit, weekends included.
We do not commit to a deadline for assessment or for remediation. We will keep you informed; promising a fix date would be promising something that, on complex findings, is not ours alone to control.
If your report concerns a client site
On the client sites we operate, Gosign is a processor, not the controller. That is not a formality: the operator decides on remediation; we receive, review and hand over verifiably.
- We forward your report without undue delay, at the latest within 24 hours, where there are indications of access to personal data - the operator's own statutory clock starts when they learn of it, and we must not delay that.
- In all other cases we forward within five working days.
- If the operator does not respond, we warn them of the risk in writing. After 90 days without remediation you may involve the BSI as coordinating body; we will not hold that against you.
What you get back
We pay no bounties. What we offer is what reporters most often say they miss:
- a case number you can point to,
- a status you can follow without an account and without signing in,
- and, if you want it, credit by name once the issue is fixed - anonymous if you prefer.
And the commitment above, in writing. We are aware that this is worth more to a reporter than a sum of money.
Our own triage is in scope too
The reporting form is assisted by a language model that helps reporters phrase their findings. That model therefore processes foreign, potentially hostile text - which is why it is explicitly part of the scope. If you can make it do something it should not, that is worth a report.
How it is contained, stated openly: the recipient and the assignment of a report are fixed before the model sees the text at all. The model has no access to tools, to the network, or to our database. Its output passes a closed schema and is discarded on any deviation rather than interpreted. It cannot close, downgrade or reroute a report - those decisions are made by a human.