How to report a security vulnerability in Alpamayo products, services or on this website.
Last updated: September 2026
Send your report by email. We accept reports in German and English. We do not run a bug bounty programme and do not pay for reports, but we credit reporters on request.
Security contact
Please use the subject line "Security" so your report is routed immediately.
We will not take legal action against researchers who report in good faith and stick to these rules:
Where our products fall under the EU Cyber Resilience Act (Regulation (EU) 2024/2847), we run a coordinated vulnerability disclosure process as required by Annex I Part II. The reporting obligations under Article 14 apply from 11 September 2026: we notify the coordinating CSIRT and ENISA of actively exploited vulnerabilities and severe incidents, with an early warning within 24 hours, a full notification within 72 hours and a final report after that.
Reports that reach us through this page feed directly into that process. If your report concerns a vulnerability that is already being exploited, say so in the subject line so we can start the 24-hour clock straight away.
Our security contact is also published as a security.txt file according to RFC 9116:
/.well-known/security.txt