Security
Report a vulnerability
Security is a priority at spot7. If you have discovered a vulnerability in a spot7 product or one of our online services, please report it to support@spot7.eu — we will take care of it.
What your report should include
To help us reproduce and fix the issue quickly, please include:
- The affected product or service, including version or URL
- A description of the vulnerability and its potential impact
- Steps to reproduce (a proof of concept, screenshots or logs help)
- Your assessment of which data or functions are affected
- A way to contact you for follow-up questions (anonymous reports are welcome)
What you can expect from us
- Acknowledgement of receipt within 48 hours
- Regular status updates until the vulnerability is fixed
- Coordinated disclosure: we agree on the timing of any publication with you
- No legal action against good-faith security research that follows the rules below
- Credit in our advisory if you wish
spot7 does not currently run a bug bounty program; reports are not remunerated.
Rules for security testing
Good-faith security research means:
- No testing that degrades the availability or integrity of our services (no DoS, no spam, no destructive testing)
- No access to third-party data beyond what is needed as proof; do not copy, modify or delete other people's data
- No social engineering, phishing or physical access to people or facilities
- Test only with your own accounts and your own devices
Scope
This policy applies to all spot7 products (hardware, firmware and companion apps) and to our online services spot7.eu, shop.spot7.eu and app.spot7.cloud.
Machine-readable contact information per RFC 9116 is available at /.well-known/security.txt on each of our domains.