Security Policy

Geltungsbereich

Diese Policy gilt für t01.li und die darunter öffentlich erreichbaren Dienste. Dienste Dritter – insbesondere Mailversand, Zahlungsabwicklung und Hosting-Infrastruktur – fallen nicht darunter; bitte wende dich dafür direkt an den jeweiligen Anbieter.

Nicht erwünscht

  • DoS-, Last- oder Stresstests jeder Art
  • Social Engineering oder Phishing gegen mich, Leser oder Dienstleister
  • physischer Zugriff auf Infrastruktur
  • Zugriff auf fremde Member-Konten oder -Daten. Falls du versehentlich auf Daten Dritter stößt: Test sofort abbrechen, nichts speichern oder weitergeben, mir Bescheid geben.
  • reine Scanner-Ausgaben ohne belegten Impact – fehlende oder „zu schwache“ HTTP-Header, SPF-/DMARC-Härtungsgrade, Clickjacking auf Seiten ohne Formular, Versionsangaben in Bannern, TLS-Konfigurationsgrade

Meldung

Per Mail an security@t01.li, gerne Deutsch oder Englisch. Hilfreich sind: betroffene URL, Reproduktionsschritte und eine kurze Einschätzung, was ein Angreifer damit konkret erreichen könnte.

Was du erwarten kannst

Ich betreibe t01.li als Einzelperson in meiner Freizeit. Es gibt keine garantierte Reaktionszeit und keinen SLA. Ich lese jede Meldung, antworte aber nur auf solche mit nachvollziehbarem Impact.

Kein Bounty

Für Meldungen wird keine Vergütung gezahlt – weder Geld noch Sachleistungen oder Gutscheine. Rechnungen, Zahlungsaufforderungen oder „Invoice“-Mails im Nachgang zu einer Meldung werden ohne Antwort verworfen. Auf Wunsch nenne ich dich nach Behebung namentlich auf dieser Seite.

Safe Harbor

Wenn du dich an diese Policy hältst, gutgläubig handelst, keine Daten Dritter abgreifst, veröffentlichst oder zerstörst und mir vor einer Veröffentlichung angemessen Zeit zur Behebung gibst, betrachte ich deine Tests als autorisiert und werde keine rechtlichen Schritte gegen dich einleiten. Diese Zusage kann ich nur für mich selbst geben – nicht für Hoster, Dienstleister oder sonstige Dritte.

Offenlegung

Bitte veröffentliche eine Schwachstelle nicht vor ihrer Behebung. Wenn ich 90 Tage nach deiner Meldung nicht reagiert habe, steht dir die Veröffentlichung frei.

Stand: 20. August 2026

English Version

This is a translation for convenience. In case of discrepancies, the German version above prevails.

Scope

This policy covers t01.li and the services publicly reachable under it. Third-party services—in particular, email delivery, payment processing and hosting infrastructure—are not covered; please contact the respective provider directly for those.

Out of bounds

  • denial-of-service, load or stress testing of any kind
  • social engineering or phishing targeting me, readers or service providers
  • physical access to infrastructure
  • accessing other people's member accounts or data. If you inadvertently come across third-party data: stop testing immediately, do not store or share anything, and let me know.
  • raw scanner output without demonstrated impact—missing or "weak" HTTP headers, SPF/DMARC hardening levels, clickjacking on pages without forms, version banners, TLS configuration grades

Reporting

By email to security@t01.li, in German or English. Helpful details: the affected URL, steps to reproduce, and a brief assessment of what an attacker could actually achieve with it.

What to expect

I run t01.li as an individual in my spare time. There is no guaranteed response time and no SLA. I read every report, but I only reply to those with demonstrable impact.

No bounty

Reports are not compensated – no money, no goods, no vouchers. Invoices, payment demands or "invoice" emails following a report are discarded without reply. On request, I will credit you by name on this page once the issue is fixed.

Safe harbour

If you follow this policy, act in good faith, do not access, publish or destroy third-party data, and give me reasonable time to fix the issue before disclosing it, I will consider your testing authorised and will not pursue legal action against you. I can only give this assurance on my own behalf – not for hosting providers, service providers or any other third parties.

Disclosure

Please do not publish a vulnerability before it has been fixed. If I have not responded within 90 days of your report, you are free to publish.

Last updated: 2026-08-20