Vulnerability Disclosure Policy

Stand: 2026-08-18

Security vulnerabilities on the website or in programs of gaijin.at can be reported confidentially to web@gaijin.at.

Communication is exclusively via email in German or English. Generally, every incoming report will be answered within one week. No response will be provided if there is suspicion of an automated or AI-generated report.

Reports without a valid email address for follow-up questions may not be processed or may only be processed inadequately.

The report should include at least the following:

The following actions are not permitted:

No legal action will be taken against the person reporting a vulnerability, provided this policy is followed. This does not apply if there is or was obvious criminal intent.

No compensation will be provided for reported security vulnerabilities or other errors.