Security policy
How to report security vulnerabilities in the website or any Dangel Studio app, and what I promise in return.
Last updated: 18 August 2026
Scope
This policy covers dangelstudio.de and every published Dangel Studio app on the Atlassian Marketplace, including future marketplace apps.
Reporting a vulnerability
Email support@dangelstudio.de, ideally with: the affected product and version (or URL), steps to reproduce, observed impact and, if available, a proof of concept. German or English are both welcome. A machine-readable version of this contact information lives at /.well-known/security.txt.
What I promise
- Acknowledgement usually within 3 business days.
- An honest assessment of whether and how I will fix the issue, and a status update once a fix is released.
- No legal action against good-faith security research that follows this policy.
- Credit as the reporter after the fix, if you want it, or none if you prefer.
Ground rules for testing
- Do not degrade services (no DoS, no spam, no social engineering).
- Do not access other people’s data beyond the minimum needed as proof; do not copy, modify or delete anything.
- Coordinated disclosure: please allow reasonable time for a fix (90 days as a guideline) before publishing details.
- There is no bug bounty programme; reports are still very welcome.
Security updates
Security updates are distributed through the Atlassian Marketplace. At minimum, the currently published version of each app is supported; channel-specific commitments are stated in each app’s documentation. What data the apps process is described in the privacy policies.