Bug Bounty Terms of Participation

Deutsche Fassung: Bug-Bounty-Teilnahmebedingungen

These terms govern participation in the bug bounty programme of Techeve, owner Tony Grätscher, Talweg 14, 07639 Bad Klosterlausnitz, Germany. An overview of the programme, its tiers and the reward ranges is available on the bug bounty page (in German).

By reporting a vulnerability to us, you confirm that you have read these terms and agree to them.

1. Who may take part

Any natural person may take part, except:

  • people working for Techeve at the time of the report, and their relatives,
  • people who contributed to the development or operation of the affected system,
  • people to whom a payment may not be made under sanctions or embargo rules.

If you are a minor, we need the consent of a parent or legal guardian before we can pay out a reward.

2. What may be tested

In scope:

  • the DNS editor (dns-editor.de) and other publicly reachable Techeve cloud applications,
  • the publicly readable source code of our open source products,
  • authentication, authorisation, data access and data protection in these systems.

Out of scope:

  • denial of service (DoS/DDoS), load testing and brute force against production systems,
  • social engineering, phishing, or physical access to people and premises,
  • plain output from automated scanners without demonstrable impact,
  • missing “best practice” headers or theoretical findings without concrete risk,
  • attacks on third-party providers or infrastructure we do not own – not even where we use their services.

Systems that recognisably belong to third parties are never part of the programme, even when they are reachable under one of our addresses.

3. Rules for testing

  • Stay with accounts and data that belong to you. Do not access other people’s personal data. If you unavoidably encounter it, stop, report it, and delete whatever you obtained.
  • Do no harm: do not delete or modify data, do not exfiltrate data, do not disrupt operations.
  • Use the least intrusive method needed for proof. A proof of concept is enough – there is no need to exploit the issue further.
  • Do not install backdoors and do not change any configuration.
  • Keep the issue confidential until we have fixed it (see section 8).
  • Do not run automated tools at an intensity that affects operations.

4. How to report

Send your report to security@techeve.de. The same contact is available in machine-readable form in our security.txt, which also links the public PGP key you can use to encrypt your report.

A useful report contains:

  • the affected system or product and, if possible, the affected version,
  • reproducible steps,
  • the impact as you see it,
  • a proof of concept where available (script, request, screenshot),
  • contact details we can reach you at.

Please report one vulnerability per report. Several findings in a single message make classification and reward assignment harder.

5. Process and timelines

  1. Acknowledgement – usually within three working days.
  2. Initial assessment – usually within ten working days we tell you whether we consider the report valid and how we classify it.
  3. Remediation – the timeframe depends on severity and effort. We keep you informed about the status.
  4. Reward – after remediation, and at the latest once classification is final.

These timelines describe the normal case and do not create a legal claim to their observance.

6. Classification

We assess every report by its actual impact, not by the effort it took to find. The levels low, medium, high and critical are described on the programme page. Classification is ours to make; if you disagree, tell us your reasoning and we will review it.

7. Rewards

  • The amounts shown on the programme page are guide values and upper limits, not commitments. The amount in an individual case depends on impact, report quality and reproducibility.
  • There is no legal claim to a reward. We decide on awards at our reasonable discretion.
  • Where the same vulnerability is reported more than once, the first reproducible report counts. Later reports are not considered, even if they are more detailed.
  • Several findings with the same root cause count as one vulnerability.
  • Issues already known to us, or already being worked on when your report arrives, are not rewarded.
  • Payment is made by bank transfer. Any taxes and duties are yours to bear; we need the details required for the transfer.
  • Breaching these terms forfeits any claim to a reward.

On request we will name you in our acknowledgements. Please tell us which name to use.

8. Disclosure

Please do not talk about the vulnerability until we have fixed it. If we cannot close a report within 90 days, we will agree the next steps with you; we will not withhold disclosure without good reason. Any publication must not contain details that endanger third parties or expose personal data.

9. Our commitment

As long as you follow these terms, we regard your testing as authorised. In that case we will not take legal action against you and will not file a criminal complaint; should proceedings arise at the instigation of others, we will confirm on request that you acted with our authorisation.

This commitment reaches only as far as we ourselves can dispose. It covers neither third-party claims nor systems outside the scope.

10. Data and confidentiality

We process your report and your contact details solely to handle the case and to pay out a reward. Details are set out in our privacy policy (in German). Third-party personal data you gain access to while testing must be treated confidentially, reported without delay and deleted afterwards.

11. Changes to the programme

We may change, suspend or end this programme and these terms at any time. For reports already received, the version published at the time of receipt applies.

12. Final provisions

German law applies. Should any provision of these terms be invalid, the validity of the remaining provisions is unaffected. In case of discrepancies between the German and the English version, the German version prevails.

Questions about the programme are welcome at security@techeve.de.

Last updated: August 2026