Security Policy & Vulnerability Disclosure

IT security is our top priority. We value the work of security researchers and the developer community in helping us keep our systems and data secure.

If you have discovered a security vulnerability in our systems or services, we ask you to report it to us as part of a responsible disclosure process (Coordinated Vulnerability Disclosure).
 

1. Getting in Touch

Please report security vulnerabilities directly to our security contact address:

Please provide as detailed a description of the vulnerability as possible (e.g. PoC, steps to reproduce, affected URLs, or parameters).
 

2. Rules of Engagement

To act within the framework of this policy and protect us as well as our users, we ask you to adhere to the following principles:

  • Respect privacy: Do not access, modify, or delete third-party personal data. If you encounter personal data during your research, stop immediately and notify us.
  • No service disruption: Do not perform Denial-of-Service (DoS/DDoS) attacks and do not use high-intensity automated scanning tools that could compromise the stability of our services.
  • No social engineering / phishing: Attacks against employees, partners, or customers (e.g. phishing, spam, social engineering) are strictly prohibited.
  • Maintain confidentiality: Do not publish details of the vulnerability before we have resolved the issue and agreed on a disclosure timeline.
     

3. Our Commitment to You

When you report vulnerabilities in accordance with this policy:

  • Acknowledgment: We typically acknowledge receipt of your report within 2 to 3 business days.
  • Remediation: We will analyze the issue promptly and keep you updated on the progress of the resolution.
  • Safe Harbor: We will not initiate legal action against you as long as you comply with these guidelines and act in good faith.
  • Recognition (optional): Upon request, we will gladly credit you by name after the vulnerability has been successfully resolved to thank you for your contribution.
     

4. Scope

In Scope:

  • Websites and online services under the domain *.marcelmarty.ch
  • Infrastructure operated by us and custom extensions/applications

Out of Scope:

  • Third-party services or externally hosted services that are not under our direct control.
  • Social engineering, spam, or phishing.
  • Volumetric attacks / Denial of Service (DoS/DDoS).
  • Reports of missing security best practices without concrete proof of exploitability (e.g. missing DMARC records without proof of abuse, pure banner-grabbing information).
     

5. Applicable Law & Jurisdiction

This policy and all resulting interactions are subject to Swiss law. Place of jurisdiction is Winterthur, Switzerland.

Last updated: July 2026