Security Policy
Responsible disclosure of vulnerabilities and security contact
Effective: 18 April 2026 · Caelex, Julian Polleschner, Berlin · Version 1.0
The security of the Caelex platform is a first-order obligation. This policy governs how you report security issues to us, the expectations we place on one another, and how we handle vulnerabilities (Coordinated Vulnerability Disclosure).
This policy supplements the technical and organisational measures in DPA Annex 1 (/legal/dpa-en) and Section 21 of the Terms V3.1.
The German version at /legal/security is the legally binding text. This English version is a convenience translation. In the event of conflict, the German text prevails.
Section 1 Reporting channel
Please report security vulnerabilities to security@caelex.eu. The machine-readable contact is published at /.well-known/security.txt in accordance with RFC 9116.
Do not report security issues via general support, social media or GitHub Issues. Those channels are not suitable for confidential reports.
Section 2 What you should report
We particularly welcome reports concerning:
- Authentication or authorisation weaknesses
- Injection vulnerabilities (SQL, XSS, command, LDAP)
- Server-Side Request Forgery (SSRF)
- Cross-Site Request Forgery (CSRF)
- Breach of tenant isolation
- Sensitive data exposure (PII, credentials)
- Misconfiguration of security-relevant headers
- Insecure session, token or cookie handling
- Circumvention of rate limits with material impact
Section 3 Safe harbour / expectations of researchers
If you conduct security testing in good faith and within the scope of this policy, and you report your findings to us, we will not pursue legal action against you (safe harbour).
Conditions:
- No impairment of platform availability (no DDoS, no load testing without prior authorisation)
- No destruction, modification or exfiltration of customer data beyond the minimum strictly necessary to demonstrate the issue
- No access to other users' accounts or data; use only your own test accounts
- No public disclosure before a mutually agreed publication date (default: 90 days from report or from patch, as jointly agreed)
- No violation of applicable law or third-party rights
- A report with sufficient detail to reproduce the issue
Section 4 Our commitment
- Acknowledgement of receipt within 2 business days
- First substantive response within 5 business days
- Ongoing progress updates
- Named credit in our Hall of Fame (see Section 6), if you so wish
- No legal action for good-faith research conducted within this policy (Section 3)
- Critical vulnerabilities are treated with highest priority
Section 5 Out of scope
This policy does not cover testing of third-party services and areas outside our control, in particular:
- Infrastructure of our sub-processors (Vercel, Neon, Upstash, Stripe, Resend, Sentry, Anthropic) — please use their own responsible-disclosure programmes
- Social-engineering attacks against staff or customers
- Physical attacks
- Denial-of-service, brute-force and volumetric testing
Section 6 Hall of Fame
We thank the following security researchers for responsible disclosure. This list is maintained with your consent; without consent, your report remains confidential.
No entries yet — we welcome your reports.
Section 7 PGP key
For particularly sensitive reports we will provide a PGP key on request. Request it at security@caelex.eu with the subject line “Request PGP key”.
Contact
CaelexSecurity contact:security@caelex.euMachine-readable contact (RFC 9116):https://www.caelex.eu/.well-known/security.txtVersion 1.0 · 18 April 2026