Security & Vulnerability Disclosure

The security of our systems and of our customers' data is a high priority for HEXLE. Despite careful development and continuous maintenance, vulnerabilities can occur. If you discover a vulnerability in one of our systems, products or services, please report it responsibly and exclusively to the contact point below.


This page is our publicly available policy on coordinated vulnerability disclosure (CVD). The machine-readable summary according to RFC 9116 is available at /.well-known/security.txt .

Contact point

E-mail: security[a]hexle.at
Alternatively via our contact form using the subject "Security".

Please use this address for security reports only. For general support or sales enquiries, please contact info[a]hexle.at .

Scope

This page is authoritative for the scope. Under RFC 9116 a security.txt file applies only to the domain it was retrieved from, but it may also apply to the products and services provided by the organisation publishing it. We serve the file on hexle.at, our subdomains and redirected domains point there, and the actual scope is the following list:

  • hexle.at and all subdomains (*.hexle.at)
  • hexle.eu (redirects to hexle.at)
  • hexle.cloud and all subdomains (*.hexle.cloud)
  • self-reservierungen.at
  • software and cloud products developed and operated by HEXLE, including the associated hosting infrastructure

Out of scope are third-party systems (e.g. data centres, upstream providers, third-party software we use, social media profiles) as well as customer systems that are not operated by HEXLE. If your report concerns such a system, we will forward it to the responsible party where possible.

What makes a good report

  • the affected system, URL, product and version
  • the type of vulnerability and a reproducible, step-by-step description
  • technical evidence such as requests, log excerpts, screenshots or a minimal proof of concept
  • your assessment of the potential impact
  • a way to contact you for follow-up questions and, if desired, the name you would like to be credited under

Rules for security research

Please stay within the following boundaries during your research. They protect personal data and the availability of our services:

  • no denial-of-service, load or brute-force attacks and no automated mass scanning that affects operations
  • no access to, modification, deletion or disclosure of third-party data. As soon as you encounter personal data, stop testing and report your finding
  • no social engineering, no phishing and no physical access to premises or staff
  • no establishment of persistence (backdoors, permanent access) and no escalation of access beyond what is necessary for proof
  • no public disclosure of the vulnerability before coordinated disclosure is complete

Process and response times

  • Acknowledgement of receipt: within 3 business days
  • Initial assessment (validity, severity, responsibility): within 10 business days
  • Remediation: depending on severity and complexity. Critical vulnerabilities are prioritised and you will receive regular status updates.
  • Coordinated disclosure: after a fix is available and in coordination with you, as a rule no later than 90 days after receipt of the report

If customers are affected, we inform them to the extent required. In the event of a personal data breach, we additionally fulfil our obligations under Art. 33 and 34 GDPR. If the vulnerability affects a product with digital elements within the meaning of EU Regulation 2024/2847 (Cyber Resilience Act) and is actively exploited, we also report it to the competent authorities (CSIRT or ENISA) within the applicable deadlines.

Assurance to reporters

If you comply with this policy, we consider your research authorised and conducted in good faith. In that case HEXLE will not initiate legal action against you and will not file a criminal complaint. Should a third party take action against you, we will confirm on request that your research was conducted under this policy. This assurance cannot exclude third-party claims and does not apply in cases of intentional damage, data exfiltration or extortion attempts.


We treat your report and your identity as confidential and will not pass them on to third parties without your consent, unless we are legally obliged to do so.

Rewards

HEXLE does not currently run a bug bounty programme and does not pay rewards for reports. On request we will credit you in the acknowledgements once the issue has been fixed.

Acknowledgements

We thank everyone who has reported vulnerabilities responsibly. There are currently no entries here. We add to this list after coordinated disclosure is complete and only with the reporter's consent.