Report a security vulnerability
Found a weakness in HelloBoss? Thank you. We treat such reports as help, not as an attack. This page states where to send it, what we commit to and what we ask of you.
Where to report
E-mail to sicherheit@helloboss.dev. The machine-readable version of this information is available under RFC 9116 at /.well-known/security.txt. Languages: German or English.
What to include
- What is affected (page, endpoint, function).
- How to reproduce it, step by step.
- What could be done with it (which data, which privileges).
- Whether you have any indication that it is already being exploited.
- How to reach you and whether you want to be credited by name.
What we commit to
- Acknowledgement within two working days (ISO/IEC 29147 allows up to five).
- First assessment within five working days: confirmed, not a defect, or still under review — with reasons.
- Remediation by severity: critical (remote code execution, authentication bypass, access to other customers' data) within 30 days, high within 60 days, medium and low in the next regular cycle. A workaround ships before the full fix where possible.
- Coordinated disclosure: we credit you by name on request once the issue is fixed, and publish nothing about you without agreement.
- No legal action against reporters who follow the rules below and act in good faith.
If a vulnerability is being exploited
If a vulnerability turns out to be actively exploited, ordosphere LLC notifies the competent authority (the relevant CSIRT respectively the platform operated by the EU Agency for Cybersecurity, ENISA) without undue delay and at the latest within three working days of becoming aware of it — as required by Article 14 of Regulation (EU) 2024/2847 from 11 September 2026. Affected customer companies are informed without undue delay. Where personal data is also breached, the 72-hour notification to the data protection authority applies in addition (Art. 33 GDPR).
What we ask of you
- Do not read, copy, alter or delete other customers' data. One proof is enough.
- No denial-of-service testing and no automated mass scanning that disrupts operations.
- No social engineering against staff or customers, no physical access attempts.
- No publication before the issue is fixed or a date has been agreed.
- Vulnerabilities in third-party components: please also report them upstream.
Not the right address for
Usage questions, lost credentials or defects without a security impact: hilfe@helloboss.dev. Questions about personal data: datenschutz@helloboss.dev.
We do not pay bounties (no bug bounty programme). As of 30 July 2026. German version: /sicherheitsluecke (prevails in case of conflict).