We sell penetration tests and build vulnerability reporting processes for our customers, so we hold our own systems to the same standard. If you find a vulnerability, we want to hear about it. We will treat your report confidentially, fix the issue as quickly as we can and keep you informed along the way.
Scope
This policy covers systems operated by DeViLink Software GmbH under the DeViLink brand:
- www.devilink-consulting.com: this website, including its forms and API endpoints
- app.devilink.ai: the Engineering Intelligence Platform (EIP) and all its modules, e.g. DevInsight and DevShield
- other subdomains of devilink-consulting.com and devilink.ai, where we operate them
Out of scope are systems run by service providers we use (e.g. CRM, email or hosting providers) and systems belonging to our customers. Please report those issues directly to the operator. If you are unsure who owns a system, contact us and we will pass your report on.
How to report
Email info@devilink-consulting.com and start the subject line with "Security:" so your report goes straight to the security team. The following details help:
- the affected system, URL or component
- the type of vulnerability and its potential impact
- steps to reproduce, ideally with a proof of concept, screenshots or request/response
- when you tested and, if available, the source IP address
- how to reach you, and whether you would like to be credited
If you would rather send details encrypted, send a short first message without technical details and we will set up a secure channel with you.
We accept reports in German and English.
What we commit to
- Acknowledgement within 3 business days
- Initial assessment (confirmed or not, severity, next steps) within 10 business days
- Remediation by severity: critical issues as fast as possible, everything else normally within 90 days
- Transparency: we keep you updated and tell you when the issue is fixed
- Credit: if you wish, we credit you by name once the issue is fixed
We do not run a bug bounty programme and do not pay rewards. We are still grateful for every report that makes our systems safer.
Rules for testing
Please test in a way that does not harm our customers or our operations:
- Access only as much data as you need to demonstrate the issue. If you come across personal or customer data, stop and report it to us.
- Do not modify or delete data, and do not create persistent access such as backdoors.
- Test only with your own accounts, never with third-party accounts or data.
- No denial of service, no spam, and no high-volume automated scanning that affects availability.
- No social engineering or phishing against staff, customers or suppliers, and no physical attacks.
- Do not share the vulnerability with others. Publish details only once it is fixed or on a date agreed with us. Unless we agree otherwise, this embargo ends 90 days after your report; after that you may publish, and the safe-harbour commitment still applies.
Safe harbour
If you act in good faith and follow this policy, we consider your research authorised. We will not take legal action against you and will not file a criminal complaint or request prosecution. This commitment does not apply to anyone who breaks these rules, for example by exfiltrating data, making extortion demands or disrupting operations.
This commitment covers only DeViLink Software GmbH and our own systems. We cannot make statements on behalf of third parties, such as suppliers or customers, or on behalf of public authorities.
What we usually do not treat as a vulnerability
We may still fix these. Without a demonstrated, concrete impact, though, we do not treat them as security reports:
- unverified output from automated scanners
- missing security headers, cookie flags, or TLS/SPF/DKIM/DMARC best-practice settings without an exploitable scenario
- version information in banners or headers
- clickjacking on pages without security-relevant actions
- self-XSS, and CSRF on forms without security impact such as logout
- missing rate limiting on non-sensitive endpoints
Machine-readable contact
The contact details in this policy are also published per RFC 9116 at /.well-known/security.txt.
Last updated: 25 September 2026