Thank you for helping keep Gabel Management’s systems and users safe. We appreciate responsible security research and coordinated vulnerability disclosure.
This policy is published by Gabel Management and constitutes authorization to perform proportionate security testing solely for the purpose of identifying and reporting security vulnerabilities, provided the testing is conducted in accordance with this policy.
If you believe you have identified a security vulnerability in a Gabel Management system, product, or repository, report it through one of the following channels:
Do not disclose the issue publicly or share details with third parties before coordinated disclosure has been completed.
Reports must include:
Reports must demonstrate a concrete and realistic security impact. Findings that only identify missing controls, configuration deviations, or best-practicerecommendations without an exploitable weakness are not considered valid vulnerability reports.
Out-of-scope, insufficient, or duplicate reports may be closed without further action.
While investigating and reporting vulnerabilities, researchers must act in good faith and minimize impact.
Testing must be limited to what is reasonably necessary to identify and demonstrate the security issue. The purpose of this policy is not to permit intentional access to or processing of data, including personal data. Any such access may occur only incidentally and solely to the extent required to demonstrate the vulnerability.
Any data, including personal data, accessed incidentally during testing must not be retained longer than necessary and must be securely deleted once the vulnerability has been demonstrated.
Researchers must:
The following are not considered security vulnerabilities on their own:
Security vulnerabilities in Gabel Management-owned applications, libraries, services, APIs, and infrastructure that meaningfully affect confidentiality, integrity, authentication, or authorization.
If there is uncertainty about whether a system or service is in scope, reporters should contact Gabel Management for clarification before starting testing.
We reserve the right to determine whether a report is in scope.
For reports that meet this policy, we commit to:
Unless otherwise agreed, we aim to complete remediation and coordinated disclosure within 90 days of the initial report.
If you act in good faith and in accordance with this policy, Gabel Management will not pursue civil or criminal action against you for activities that arereasonably necessary to identify and report a security vulnerability.
This does not apply to malicious, reckless, or out-of-scope activity.
Please indicate whether you would like public attribution. If no preference is stated, no attribution will be made.
Gabel Management does not operate a bug bounty or financial reward program.
This policy is published in English. Vulnerability reports may be submitted in English or German.