OYSI GmbH takes the security of its systems and the data entrusted to it seriously. We appreciate the work of security researchers who help us identify and resolve vulnerabilities responsibly. This policy describes how to report a vulnerability to us and what you can expect in return.
Reporting
Please report security vulnerabilities by e-mail to [email protected]. Reports may be written in German, English or French. Our machine-readable contact information is published at /.well-known/security.txt in accordance with RFC 9116.
We aim to acknowledge and review reports as promptly as reasonably possible.
What to include
- The affected domain, URL or service.
- A description of the vulnerability and its potential impact.
- Steps to reproduce the issue, including a proof of concept where possible.
- The date and time of your observation.
- Optionally, your name or handle and a way to contact you for follow-up questions.
Research guidelines
- Act in good faith to avoid privacy violations, destruction of data and interruption or degradation of our services.
- Only interact with accounts you own or with explicit permission of the account holder.
- If you encounter personal data, confidential information or credentials, stop testing immediately, do not store or share the data and include this in your report.
- Limit your testing to what is necessary to demonstrate a vulnerability.
- Report the vulnerability to us promptly after discovery.
Prohibited activities
- Denial-of-service attacks, resource exhaustion or any testing that degrades the availability of our services.
- Social engineering, phishing or physical attacks against OYSI employees, partners or infrastructure.
- Accessing, modifying, exfiltrating or deleting data that does not belong to you.
- Spam, brute-force attacks, automated mass scanning or the use of exploits beyond the minimum needed to prove an issue.
- Pivoting to further systems, establishing persistence or otherwise going beyond the initial finding.
- Publicly disclosing a vulnerability before we have had a reasonable opportunity to address it.
Scope
This policy applies to publicly reachable systems operated by OYSI GmbH under the domains oysi.gmbh and oysi.tech. Systems operated by third parties on our behalf and services of other companies are not covered by this policy; please report issues with such services to the respective provider.
Authorization
This policy is not a blanket authorization for penetration testing. Any testing must remain within the research guidelines and the prohibited activities described above. Testing that goes beyond these limits is not authorized by this policy.
Bounty
OYSI does not operate a bug bounty programme. Submission of a vulnerability report does not create an entitlement to financial compensation. OYSI may, at its sole discretion, recognize particularly valuable reports.
Confidentiality and coordinated disclosure
We treat reports and the identity of reporters confidentially and do not share personal data of reporters with third parties without consent, unless required by law. We ask you to keep the details of a reported vulnerability confidential until we have had a reasonable opportunity to investigate and remediate the issue. Where appropriate, we are happy to coordinate public disclosure with you once remediation is complete.
Good-faith research
OYSI does not intend to pursue legal action against researchers who act in good faith and comply with this policy. This statement does not authorize testing beyond the scope and conditions described in this policy.
Last updated: 27 September 2026