🔒 Responsible Disclosure
Vulnerability Disclosure Policy
Purpose
COSIC takes the security of its products and services seriously. This policy describes how security researchers can responsibly report vulnerabilities and how COSIC will respond.
Report a Vulnerability
Please report vulnerabilities via email to security@cosic.eu. Please include the following information:
- Affected product or system (e.g. cosic.eu, MANTIS, NEAT)
- Description of the vulnerability and potential impact
- Steps to reproduce
- Your contact details for follow-up (optional but recommended)
Rules for Researchers
- Do not exploit vulnerabilities or access other people's data
- Do not perform denial-of-service attacks
- Do not modify or delete data
- Do not publicly disclose the vulnerability before it is fixed
- Comply with applicable laws
Our Response
- Acknowledgement of receipt within 3 business days
- Initial assessment and prioritisation within 10 business days
- Regular updates on remediation status
- Notification once the vulnerability is resolved
Scope
This policy applies to the following products and services:
- cosic.eu
- shop.cosic.eu
- MANTIS
- NEAT
Out of Scope
- Social engineering (phishing, pretexting)
- Physical attacks
- Vulnerabilities in third-party services (e.g. FastSpring)
- Automated vulnerability scans without permission
Legal Protection
If you comply with this policy, we will not take legal action against you. We consider your research as authorised security testing under applicable law.