PurposeThe security of our websites, applications and publicly accessible services is important to us.
If you believe you have discovered a security vulnerability in a system operated by us, we appreciate responsible reporting so that we can investigate and address the issue.
How to Report a VulnerabilityPlease report potential security vulnerabilities by email to:
info@von.caron.dePlease include, where possible:
- a clear description of the vulnerability;
- the affected website, application or service;
- steps required to reproduce the issue;
- relevant technical information; and
- a proof of concept, if appropriate.
Please do not include personal data or other sensitive information unless it is strictly necessary to describe the vulnerability.
ScopeThis policy applies to publicly accessible websites, applications and services operated by Joachim von Caron, including:
-
caron.de and its subdomains;
- publicly accessible services and APIs operated directly by us; and
- our own applications where a security vulnerability may affect our systems or users.
Third-party services and infrastructure that we do not operate are outside the scope of this policy.
Responsible TestingWhen investigating a potential vulnerability, please:
- limit testing to what is necessary to demonstrate the vulnerability;
- do not intentionally access, modify, copy or delete data belonging to other users;
- do not perform denial-of-service or resource-exhaustion attacks;
- do not send spam or conduct phishing or social-engineering attacks;
- do not install malware or persistent access mechanisms;
- avoid automated or high-volume scanning that could affect the availability or performance of our services; and
- keep information about an unresolved vulnerability confidential until we have had a reasonable opportunity to investigate and address it.
If you encounter personal, confidential or otherwise sensitive information, stop accessing the affected data and report the issue to us.
What You Can Expect From UsWe will review vulnerability reports and aim to respond as soon as reasonably possible.
We may contact you for additional information required to reproduce or understand the issue.
If you act in good faith, comply with this policy and limit your activities to responsible security research, we will not initiate legal action against you solely for conducting and reporting that research.
We appreciate coordinated disclosure and will work with reporters where appropriate to determine a reasonable timeframe before public disclosure.
No Bug BountyUnless explicitly agreed otherwise in writing, this Responsible Disclosure Policy does not constitute a bug bounty program and does not create an entitlement to financial compensation or other rewards.
Changes to this PolicyThis policy may be updated from time to time to reflect changes to our systems or security practices.
Last updated: August 2026