Security & Vulnerability Disclosure
Last Updated: 25.09.2026
If you have found a security vulnerability in Wullup, please tell us. This page explains how to report it, which rules apply to your research and what you can expect from us.
1. How to Report
Email [email protected] with the subject "Security", in German or English. Please include:
- what is affected (URL, app screen, app version, device);
- a description of the vulnerability and its possible impact;
- the steps to reproduce it, ideally with a proof of concept;
- whether you would like to be credited, and under which name.
We do not currently offer a PGP key. Please do not include other people's personal data in your report. If you need to share sensitive details, write to us first and we will agree on a way to send them.
Our security.txt (RFC 9116) is available at https://wullup.com/.well-known/security.txt.
2. Scope
In scope:
- wullup.com and its subdomains, in particular api.wullup.com, backstage.wullup.com (Wullup Backstage) and join.wullup.com;
- the Wullup apps for iOS and Android, in their current versions from the App Store and Google Play.
Internal tools on our subdomains (e.g. admin and analytics systems): please report any findings, but do not test them. This means no login attempts and no password guessing.
Out of scope:
- vulnerabilities in the products of third parties we use (e.g. Cloudflare, Stripe, Google, Apple, Expo, OpenAI). Please report these to the provider. Misconfigurations on our side are in scope;
- social engineering, phishing and physical attacks on our staff, users or premises;
- denial of service, load or volumetric tests, and spam;
- automated scans that degrade the service or generate heavy traffic;
- findings without demonstrable security impact, e.g. missing security headers or best-practice recommendations without an exploitable scenario.
3. Rules for Your Research
- Use only your own accounts and your own test data.
- Do not change or delete other users' data. Access it only to the minimum extent needed to prove the vulnerability.
- Stop as soon as you have proven the vulnerability, and report it to us promptly.
- Do not copy or pass on data, and do not keep access to our systems (e.g. through backdoors).
- Do not disrupt the service: no denial of service, no spam, no social engineering.
- Keep the vulnerability confidential until it is fixed (Section 5).
4. Safe Harbour
If you act in good faith and follow these rules:
- we regard your research as authorised by us;
- we will not take civil action against you (e.g. claims for damages or injunctions);
- we will neither file a criminal complaint (Strafanzeige) nor a request for prosecution (Strafantrag) against you.
This commitment covers only our own systems and our own claims. It cannot bind public prosecutors, courts or third parties (e.g. other providers or affected users). If you are unsure whether something is covered, ask us before you act.
5. What We Do
- Receipt: We confirm receipt of your report. Our target is to do so within 5 working days.
- Assessment: We assess the report and keep you informed about our progress.
- Fix: We fix confirmed vulnerabilities as quickly as we reasonably can, prioritised by severity.
- Coordinated disclosure: Please do not publish details until we have fixed the vulnerability or 90 days have passed since your report, whichever is earlier, unless we agree otherwise with you.
- Credit: If you wish, we will name you as the finder when we mention the fix publicly.
6. No Bug Bounty
We do not run a bug bounty programme and do not pay rewards. Demanding payment in return for not disclosing a vulnerability is not good-faith research.
7. Personal Data
If you come across personal data during your research, access it only as far as needed to prove the vulnerability, and tell us what you accessed. Do not keep the data, and delete it once you have reported the vulnerability. We process your report and your contact details to handle the report; see our Privacy Policy.
This document is available in German and English. The German version is legally binding; the English version is a courtesy translation.