1. Scope
If you find a security vulnerability in our systems or products, we want to hear about it. This page explains how to report it, what we commit to and which rules apply.
It covers
- the website setix.net,
- the services SETIX.NET operates itself, such as mail, DNS, hosting and the customer portal,
- software and devices that SETIX.NET makes or supplies, such as the zxOfficeBox.
If the vulnerability affects a website or system we operate for a customer, please report it to us as well; we will inform the customer. Do not test any further there, though. Please report vulnerabilities in other vendors’ products to the respective vendor.
2. How to report
Write to info@setix.net with the subject “Security vulnerability”. Reports in English or German are welcome. Helpful details are:
- the affected address, product or version,
- the steps to reproduce the vulnerability,
- what an attacker could achieve with it,
- how we can reach you if we have questions.
Do not send us any credentials or personal data you came across – a description is enough.
3. What we commit to
- We acknowledge receipt within five working days.
- We share our initial assessment within 14 days.
- We keep you informed until the vulnerability is fixed.
- If you wish, we credit you as the finder when we publish.
We do not pay rewards.
4. Disclosure
We coordinate disclosure with you. As a rule, it takes place once the vulnerability is fixed, and no later than 90 days after your report unless agreed otherwise. If a vulnerability is already being exploited, we inform those affected earlier. We meet statutory reporting obligations, for example under the Cyber Resilience Act, regardless.
5. Rules
- Test only as far as needed to demonstrate the vulnerability.
- Do not access, modify or delete third-party data. If you come across such data anyway, stop and let us know.
- Do not disrupt operations: no load or denial-of-service tests, no spam.
- No deception of our staff or customers, no access to premises or devices.
- Do not share the vulnerability before we have agreed on disclosure.
6. Our assurance
If you act in good faith and follow these rules, we will not file a criminal complaint against you or take any other legal action. This assurance applies to SETIX.NET; it cannot bind third parties or authorities.
The German version is authoritative.