Contact: mailto:hello@kauz.gmbh Expires: 2027-09-14T23:59:59.000Z Encryption: https://kauz.gmbh/pgp.asc Encryption: openpgp4fpr:5F01B82CA56A261DAAD464BCB270C72F4A0A61AF Policy: https://kauz.gmbh/security-policy/ Canonical: https://kauz.gmbh/.well-known/security.txt Preferred-Languages: en, de # Kauz Security Services GmbH # Please read the policy above before testing. Summary: # # In scope: kauz.gmbh, www.kauz.gmbh, mta-sts.kauz.gmbh, our DNS/mail/TLS # configuration, and configuration issues specific to our # storage.kauz.gmbh instance. # # Out of scope: Our clients' systems. Nothing here authorises testing against # any client system, including any referenced on this site. # Nextcloud itself -> https://hackerone.com/nextcloud (Hetzner # operates the instance; our misconfiguration is in scope). # Third-party providers we use but do not run (Cloudflare, # GitHub, mailbox.org, Hetzner). brutalist.systems, which is a # separate project. # # The policy lists findings we have already assessed and will not act on. # No bug bounty. For genuinely time-critical issues, put "URGENT SECURITY" # in the subject line.