security

Security and Vulnerability Reporting

How to report a security vulnerability in Alpamayo products, services or on this website.

Last updated: September 2026

Report a vulnerability

Send your report by email. We accept reports in German and English. We do not run a bug bounty programme and do not pay for reports, but we credit reporters on request.

Security contact

Please use the subject line "Security" so your report is routed immediately.

What to include

  • The affected product, service or URL, plus version or deployment if you know it
  • A description of the vulnerability and its likely impact
  • Steps to reproduce it, ideally with a proof of concept
  • Whether the issue is already public or being actively exploited
  • How we can reach you for follow-up questions

What happens next

  1. We confirm receipt of your report within 3 business days.
  2. Within 10 business days we send you an initial assessment with our severity rating and how we plan to handle it.
  3. We keep you updated while we work on a fix and agree a disclosure date with you.
  4. We ship the fix through our regular update and revision process and inform affected customers.

Ground rules for testing

We will not take legal action against researchers who report in good faith and stick to these rules:

  • Do not access, change or delete data that is not yours, and stop as soon as you have confirmed a vulnerability.
  • No denial-of-service tests, spam, social engineering or physical attacks.
  • Do not test systems that Alpamayo operates for a customer without that customer's consent.
  • Give us reasonable time to fix the issue, normally 90 days, before you publish.

Scope

In scope

  • alpamayo-solutions.com and its subdomains, including the customer portal
  • PREKIT hub and edge software, its services and UI plugins
  • Deployments and infrastructure operated by Alpamayo

Out of scope

  • Third-party services we only use, such as hosting, email or analytics providers. Report those to their vendor.
  • Findings without realistic security impact, such as missing best-practice headers, self-XSS or raw scanner output without a working attack.
  • Customer systems that Alpamayo does not operate.

Cyber Resilience Act

Where our products fall under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), we run a coordinated vulnerability disclosure process as required by Annex I Part II. The reporting obligations under Article 14 apply from 11 September 2026: we notify the coordinating CSIRT and ENISA of actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours, a full notification within 72 hours and a final report after that.

Reports that reach us through this page feed directly into that process. If your report concerns a vulnerability that is already being exploited, say so in the subject line so we can start the 24-hour clock straight away.

Machine-readable contact

Our security contact is also published as a security.txt file according to RFC 9116:

/.well-known/security.txt