Kauz Security Services

Vulnerability Disclosure Policy

We welcome reports about security issues in our own infrastructure. This page sets out what is in scope, what we ask of you, what we can offer legally, and what you can expect back. This is also the policy referenced from our security.txt.

Kauz Security Services GmbH is a one-person consultancy. We do not run a bug bounty and we have no triage team. What we can offer is a prompt, technically competent reply from someone who does this work for a living.

Scope

In scope:

Out of scope:

Findings we will not act on

This list exists so you do not spend time on something we have already assessed. It is not a claim that these never matter, only that on a static brochure site with no accounts, no forms, and no state-changing actions, they do not.

If you believe one of these does have real impact here, send it with the impact demonstrated and we will look properly.

What we ask

Not authorised under any circumstances: denial-of-service or load testing, physical access attempts, social engineering of us or anyone connected to us, and any action affecting a third party.

German criminal law has no general concept of “authorised access” comparable to the US Computer Fraud and Abuse Act, and most published disclosure-policy templates are drafted for US law. What follows is what German law actually lets us offer, and where its limits are. It is our reading of the statute, not legal advice.

Consent. §§ 202a and 202b StGB penalise access that is unbefugt (unauthorised). Where the party entitled to the data consents to the access, the access is not unauthorised and no offence is committed. For the systems we operate, and within the scope and rules set out above, this policy is that consent. Research that stays inside it is not a crime we choose not to prosecute; it is not a crime.

Where our consent does not reach. We can only consent for what is ours. The website is served by GitHub and Cloudflare, and storage.kauz.gmbh runs on Hetzner’s infrastructure. Our consent covers our content and our configuration on those services, not the provider’s platform underneath. It does not cover our clients or any third party.

Strafantrag. Offences under §§ 202a, 202b and 202d StGB, and under § 303a StGB, are prosecuted only on application by the injured party (§ 205 Abs. 1 and § 303c StGB), and that application is ours to make or withhold. For research carried out in good faith under this policy, including honest mistakes at the edge of scope:

What we cannot offer. Three real limits, stated because pretending otherwise would be worthless to you:

Reporting

One channel: hello@kauz.gmbh. Please encrypt anything sensitive.

A useful report contains the affected URL or host, the request, what you observed, and what an attacker gets from it. Put URGENT SECURITY in the subject line if it is genuinely time-critical.

English or German, whichever you prefer.

What to expect

We do not pay bounties and we are not going to pretend that is under review. We are also frequently in client engagements, which occasionally makes us slower than the times above; if that happens we will tell you rather than go quiet.