Vulnerability Reporting

How to report

  • Email: security@wx1.de
  • Provide as much detail as possible (steps to reproduce, impact, environment).
  • Do not exploit the vulnerability beyond the scope necessary to demonstrate the issue.

Important Legal Notice

There is no claim to compensation for the reporting of vulnerabilities or for research activities carried out in connection with them.

WX-ONE reserves the right to grant a reward if we deem it appropriate.

We do not accept security reports that demand advance payment. Such requests will be reported to the proper authorities immediately.

We strongly encourage security researchers to notify us of their planned activities in advance. Research activities that are not conducted in good faith may result in scans of our infrastructure being reported to the authorities.

To prevent this and to ensure that legitimate security research is not obstructed, please provide us with the source IP addresses from which testing will be conducted.

In Scope

We accept reports for vulnerabilities in WX-ONE cloud services (Compute, Managed Kubernetes, Object Storage, Block Storage) and our customer-facing interfaces.

Out of Scope

• Denial of Service (DoS/DDoS) attacks or simulated DoS/DDoS • Social engineering of WX-ONE employees • Vulnerabilities obtained through the compromise of customer or employee accounts • Physical attacks against our employees, offices, or data centers • Targeting assets of WX-ONE customers or non-WX-ONE sites • Browsing, searching, or copying publicly available data • Non-default configuration issues or changes made using valid credentials • Unsolicited bulk messages (spam)

Good Faith Security Research

• Your research must be conducted with the primary goal of identifying and correcting security flaws. • You must not disrupt our systems, destroy data, or violate the privacy of others. • If a vulnerability provides unintended access to data, access only the minimum required for a proof of concept and stop immediately if you encounter customer data (personal, financial, or proprietary information). • Report findings to us within 72 hours of discovery. • Provide us with a reasonable amount of time to resolve the issue before any public disclosure. • Only interact with accounts you own or for which you have explicit written permission. • No stunt hacking, extortion, or harassment.

Responsible Disclosure Policy

We acknowledge the reception of security vulnerabilities and will treat all submitted reports as high priority.

1We will get back to you within 48 hours (on business days) to confirm receipt of your report.
2We will prioritize and develop a fix or mitigation.
3We will notify the reporter of the status.
4Once resolved, we may publish a security advisory and include the reporter's name (unless anonymity is requested).

Security Advisories

We maintain an online register of known vulnerabilities and security advisories related to the WX-ONE platform.

Advisory IDTitleDateSeverityStatus
No security advisories currently published.

Security Contacts

For security-related inquiries or reporting:

Organization

WizardTales GmbH