Status: So far only this website is publicly reachable. The mail service is in development and not yet in scope. There is no bounty programme.
How to report
Write to hello@patchletter.com, in German or English. We will publish a dedicated OpenPGP key for reports before the mail service launches. Until then, please send only a short description without exploitable details at first. We will then agree a confidential channel with you for the rest.
It helps to include:
- the affected address and the time of your observation,
- the steps needed to reproduce the behaviour,
- your assessment of the impact,
- whether and how you would like to be credited.
What we commit to
- We reply within 72 hours.
- We keep you informed about assessment and remediation.
- After the fix we publish together with you, if you wish.
- We credit you as the finder, provided you agree.
What is in scope
| In scope | Out of scope |
|---|---|
| the website at lettron.eu and www.lettron.eu | third-party systems, such as those of hosting, DNS or certificate providers |
| its delivery: TLS, security headers, redirects | denial-of-service attacks and automated mass requests |
| the published transparency files and their signature | deceiving people and physical access |
| reports without a demonstrable impact, such as bare version numbers |
Rules for testing
- Test only as far as needed to demonstrate the issue.
- Do not access other people's data, and do not change or delete anything.
- Do not impair availability.
- Give us time to fix the issue before you publish details.
Anyone who follows these rules is, in our view, acting in good faith. A legally reviewed statement waiving legal action (safe harbour) is planned before the mail service launches.
The machine-readable version is at /.well-known/security.txt. The architecture and the planned reviews are described under Security.