How we secure this site
netzreporter.org is served over HTTPS with HSTS, a strict Content-Security-Policy, and modern cross-origin isolation headers. Analytics are consent-gated: nothing loads from Google Tag Manager unless you choose "Accept all" on the cookie banner. We operate no web contact form, so no enquiry data is stored in a website database — email reaches us directly.
How we handle investigation data
Threat intelligence work involves sensitive material: client brand data, evidence of live attacks, and sometimes personal data belonging to victims. We hold it under the terms in our privacy policy, apply data minimisation and defined retention, and can sign a data processing agreement as part of an engagement.
Reporting a vulnerability
If you believe you have found a security vulnerability in this website, we want to hear from you. Email [email protected] with:
- a description of the issue and where you found it;
- the steps needed to reproduce it; and
- the potential impact as you see it.
Please give us a reasonable chance to investigate and fix it before disclosing publicly. We will acknowledge your report, keep you updated, and credit you if you would like once it is resolved.
Please do not
- Access, modify or delete data that is not yours, or degrade the service for others (no denial-of-service or spam testing).
- Use social engineering, phishing, or physical attacks against our people or infrastructure.
- Run high-volume automated scans.
Safe harbor
If you make a good-faith effort to follow this policy, we will treat your research as authorised and will not pursue or support legal action against you for it. If you are unsure whether an action is acceptable, ask first at [email protected].
A machine-readable version of this contact is published at /.well-known/security.txt.
Related: Trust & Evidence · Privacy Policy · Contact