Report abuse or security issues

Found a security vulnerability in one of our offerings, or a phishing email pretending to be us? Thank you for letting us know. The sooner we hear about it, the faster we can protect our customers.

Which domains belong to us

These domains belong to us, each with all of its subdomains.

  • on-promise.cloud
    • on-promise-cloud.com
    • on-promise-cloud.de
  • startup-business-cockpit.de
  • grounds-up.coffee
    • grounds-up.de
  • secure-vibe-coding.de
    • secure-vibe-coding.com
  • driftguard.de

What you can report

  • Security vulnerabilities on any of the domains listed above
  • Phishing and fraud: emails, links or websites that pretend to be us but come from none of these domains
  • Misuse of our services

What helps us

  • What happened, in your own words
  • The affected URL
  • Time, including time zone
  • Technical details, such as request and response, screenshots or debug output
  • How we can reach you with questions

How to reach us

security@on-promise.cloud

Our contact details are also available in machine-readable form at /.well-known/security.txt

What happens next

We look into every report and get back to you. A real security issue means stop-the-line for us: it takes priority over everything else. What we learn from it, we later share openly in the compendium, so others don't fall into the same trap.

We do not run a bug bounty programme and pay no rewards for reports. You have our thanks all the same.

Reporting in good faith

If you look for vulnerabilities on the domains listed above in good faith and report them to us, we will not take legal action against you. In return, we ask you to:

  • test only as far as needed to demonstrate the issue,
  • not access, change or delete other people's data, and not pass on any data you come across,
  • not disrupt operations, so no load or denial-of-service tests and no social engineering,
  • only make the issue public once we have fixed it or agreed on it together.

Third-party services we use are not covered. Please report issues there directly to the respective provider.

Confidential

We treat every report confidentially and keep it only as long as the law requires. More on this in the Privacy Policy.

Frequently asked questions

I'm not sure it really is a vulnerability. Should I report it anyway?

Yes, better once too often than once too few. We'll look into it and tell you what we make of it.

I received a suspicious email. What should I do?

Don't click any links in it and don't enter any data. Ideally, forward the email as an attachment to security@on-promise.cloud; that keeps the technical headers that help us assess it.

May I write about my finding?

Gladly, once the issue is fixed or we have agreed on a date together. If you like, we'll mention you when we write about it in the compendium.

Does this also cover services you use, such as your cloud provider?

No. Please report issues with third-party providers directly to them. If you're unsure whether something belongs to us, check the domain list above or just write to us.

Do you pay a reward?

No, we don't run a bug bounty programme. You have our thanks all the same.