Vulnerability Disclosure Policy

Vulnerability Disclosure Policy

Last updated on 4/14/2025

The security of our platform and the protection of our users are of utmost priority for Superchat. A key element of our security strategy is the early identification and resolution of vulnerabilities. We value collaboration with the security research community and believe this cooperation significantly contributes to the continuous improvement of our security architecture.

We encourage security researchers to confidentially report potential security vulnerabilities to our development team before disclosing them publicly. Our goal is to identify and fix vulnerabilities before they can be exploited.

Our Commitments

Scope

In Scope:

Out of Scope:

Reporting Process

1. Submitting a Report

If you have discovered a potential security vulnerability in our products or services, please contact us via email at security@superchat.de.

Please use this channel exclusively for security reports. For general software issues, kindly contact our regular support.

2. Required Information

Please provide as much relevant information as possible:

Please submit a separate report for each discovered vulnerability.

3. Open Source Components

We use various open source components in our products. If you discover a vulnerability in such a component, we ask you to:

4. Responsible Conduct

When searching for security issues, please:

Our Response Process

Disclosure Timeline

We aim to follow this timeline:

For complex issues, this timeline may be adjusted in coordination with the reporter.

Miscellaneous Information

We are grateful for all reports regarding IT security-related issues, however we do not offer monetary compensation.

Contact

If you have any questions regarding this policy or the reporting process, please contact our security team at security@superchat.de.

Thank you for helping secure the Superchat platform!