Website online. Mail service in development; launch follows security reviews.Current status

Report a vulnerability

How to report a security issue to us, what we commit to and what is off limits when testing.

Status: So far only this website is publicly reachable. The mail service is in development and not yet in scope. There is no bounty programme.

How to report

Write to hello@patchletter.com, in German or English. We will publish a dedicated OpenPGP key for reports before the mail service launches. Until then, please send only a short description without exploitable details at first. We will then agree a confidential channel with you for the rest.

It helps to include:

  • the affected address and the time of your observation,
  • the steps needed to reproduce the behaviour,
  • your assessment of the impact,
  • whether and how you would like to be credited.

What we commit to

  • We reply within 72 hours.
  • We keep you informed about assessment and remediation.
  • After the fix we publish together with you, if you wish.
  • We credit you as the finder, provided you agree.

What is in scope

In scopeOut of scope
the website at lettron.eu and www.lettron.euthird-party systems, such as those of hosting, DNS or certificate providers
its delivery: TLS, security headers, redirectsdenial-of-service attacks and automated mass requests
the published transparency files and their signaturedeceiving people and physical access
reports without a demonstrable impact, such as bare version numbers

Rules for testing

  • Test only as far as needed to demonstrate the issue.
  • Do not access other people's data, and do not change or delete anything.
  • Do not impair availability.
  • Give us time to fix the issue before you publish details.

Anyone who follows these rules is, in our view, acting in good faith. A legally reviewed statement waiving legal action (safe harbour) is planned before the mail service launches.

The machine-readable version is at /.well-known/security.txt. The architecture and the planned reviews are described under Security.