← Back to login

Report a security vulnerability

Found a weakness in HelloBoss? Thank you. We treat such reports as help, not as an attack. This page states where to send it, what we commit to and what we ask of you.

Where to report

E-mail to sicherheit@helloboss.dev. The machine-readable version of this information is available under RFC 9116 at /.well-known/security.txt. Languages: German or English.

What to include

What we commit to

If a vulnerability is being exploited

If a vulnerability turns out to be actively exploited, ordosphere LLC notifies the competent authority (the relevant CSIRT respectively the platform operated by the EU Agency for Cybersecurity, ENISA) without undue delay and at the latest within three working days of becoming aware of it — as required by Article 14 of Regulation (EU) 2024/2847 from 11 September 2026. Affected customer companies are informed without undue delay. Where personal data is also breached, the 72-hour notification to the data protection authority applies in addition (Art. 33 GDPR).

What we ask of you

Not the right address for

Usage questions, lost credentials or defects without a security impact: hilfe@helloboss.dev. Questions about personal data: datenschutz@helloboss.dev.

We do not pay bounties (no bug bounty programme). As of 30 July 2026. German version: /sicherheitsluecke (prevails in case of conflict).

Verträge hier kündigen
ImpressumDatenschutzAGBWiderruf und KündigungErstattungLeistungserbringungAuftragsverarbeitungBetroffenenrechteHaftungsausschlussSo arbeitet die KISicherheitslücke melden