Reporting security vulnerabilities
Last updated: September 2026
We take security reports seriously and welcome them. This page describes how to reach us, what we do with a report and what you can expect from us in return.
How to report
Please send your report by email. Do not disclose the issue publicly before we have had the chance to fix it.
We read reports in German and English.
A useful report contains:
- Which component is affected (website, licence server, desktop app) and which version.
- Steps to reproduce the issue, as precisely as possible.
- What an attacker could achieve with it.
- How we may credit you, if you would like to be named.
Scope
This policy covers the components we operate and ship ourselves:
- The website flowbotcommander.com including the customer account.
- The licence server and its interfaces under /api/.
- The FlowBotCommander desktop application and its update mechanism.
Out of scope are third-party services we merely use (for example PayPal or our hosting provider) — please report issues there directly to the provider concerned.
What you can expect from us
- We confirm receipt of your report within 72 hours.
- We tell you our assessment and the planned course of action within ten working days.
- Once fixed we inform you, and on request we name you in the release notes.
Good-faith research
If you research in good faith and stick to the rules below, we will not take legal steps against you and will not report you:
- Only access data that belongs to you; stop as soon as you reach third-party data.
- Do not delete or alter data, and do not impair availability (no denial-of-service tests, no mass requests).
- Give us reasonable time to fix the issue before you publish anything.
We do not operate a paid bug bounty programme. A report is voluntary and does not create any claim to payment.
Machine-readable contact
The same contact details are available in machine-readable form at /.well-known/security.txt in accordance with RFC 9116.