Report a vulnerability

Found a weakness in NODE64? Write to us — plain email is fine for first contact. This page explains what happens next.

Address for security reports

security@node64.de

Please do not use the contact form or support — nobody reads those with this level of urgency.

The same information, machine-readable, is in our security.txt as defined by RFC 9116. /.well-known/security.txt

What we promise

  • We acknowledge receipt within 24 hours — weekends included.
  • Within 7 days you get an assessment: confirmed, not confirmed, or we need more.
  • We keep you posted until the matter is closed.
  • If you want credit, we name you once the hole is closed. If you prefer not, we do not.
  • Stick to the rules below and you will face no criminal complaint and no cease-and-desist from us.

What we expect

  • Give us time before you publish. 90 days is the guideline; if we are faster, we will say so.
  • No third-party data. If you reach customer data, stop, tell us, and delete what you hold.
  • No denial of service, no spam, no social engineering against us or our customers.
  • Test with your own account. A free account covers almost everything — if you need more, ask.
  • Send us enough to reproduce it: steps, affected address, timestamp.

What this covers

In scope

  • node64.de, app.node64.de and get.node64.de
  • The agent in every published build, including the install script and container images
  • The API and the ingest path agents use to deliver their data

Out of scope

  • Installations our customers run on their own servers — those are not ours
  • Third-party services we use (payment processing, data centre)
  • Missing hardening advice with no concrete security impact, and raw scanner output

What happens with your report on the regulatory side

Since 11 September 2026 the Cyber Resilience Act obliges manufacturers to report actively exploited vulnerabilities to ENISA and the national CSIRT within 24 hours. So if your report concerns a vulnerability that is demonstrably being exploited, we pass on the technical details — your name and contact details only with your explicit consent.

Credits

This is where we name the people who pointed out a hole. The list is still empty — neither a good nor a bad sign, we are simply young.