Security Policy & Vulnerability Disclosure
IT security is our top priority. We value the work of security researchers and the developer community in helping us keep our systems and data secure.
If you have discovered a security vulnerability in our systems or services, we ask you to report it to us as part of a responsible disclosure process (Coordinated Vulnerability Disclosure).
1. Getting in Touch
Please report security vulnerabilities directly to our security contact address:
- Email: contact(at)marcelmarty.ch
- PGP Key: For encrypted communication, please use our OpenPGP key at https://www.marcelmarty.ch/.well-known/pgp-key.txt
- Languages: German, English
Please provide as detailed a description of the vulnerability as possible (e.g. PoC, steps to reproduce, affected URLs, or parameters).
2. Rules of Engagement
To act within the framework of this policy and protect us as well as our users, we ask you to adhere to the following principles:
- Respect privacy: Do not access, modify, or delete third-party personal data. If you encounter personal data during your research, stop immediately and notify us.
- No service disruption: Do not perform Denial-of-Service (DoS/DDoS) attacks and do not use high-intensity automated scanning tools that could compromise the stability of our services.
- No social engineering / phishing: Attacks against employees, partners, or customers (e.g. phishing, spam, social engineering) are strictly prohibited.
- Maintain confidentiality: Do not publish details of the vulnerability before we have resolved the issue and agreed on a disclosure timeline.
3. Our Commitment to You
When you report vulnerabilities in accordance with this policy:
- Acknowledgment: We typically acknowledge receipt of your report within 2 to 3 business days.
- Remediation: We will analyze the issue promptly and keep you updated on the progress of the resolution.
- Safe Harbor: We will not initiate legal action against you as long as you comply with these guidelines and act in good faith.
- Recognition (optional): Upon request, we will gladly credit you by name after the vulnerability has been successfully resolved to thank you for your contribution.
4. Scope
In Scope:
- Websites and online services under the domain *.marcelmarty.ch
- Infrastructure operated by us and custom extensions/applications
Out of Scope:
- Third-party services or externally hosted services that are not under our direct control.
- Social engineering, spam, or phishing.
- Volumetric attacks / Denial of Service (DoS/DDoS).
- Reports of missing security best practices without concrete proof of exploitability (e.g. missing DMARC records without proof of abuse, pure banner-grabbing information).
5. Applicable Law & Jurisdiction
This policy and all resulting interactions are subject to Swiss law. Place of jurisdiction is Winterthur, Switzerland.
Last updated: July 2026