Responsible Disclosure
Redlings finds vulnerabilities in products, firmware, protocols and platforms, on behalf of clients and in independent research. How we handle them depends on the context in which the vulnerability was discovered. This page describes both paths unambiguously.
Client assessments: Confidentiality without exception
Everything we find during an assessment you have commissioned, vulnerabilities, exploits, credentials, architecture details, is exclusively your property and remains confidential. No finding from a client assessment will ever be mentioned, alluded to, or published to any third party without your explicit, written approval.
This applies without exception and without expiry:
- No publication: We do not publish findings from client assessments, not anonymized, not after years, not after project completion.
- No sharing: We do not share findings with anyone other than your designated project team.
- No CVE requests: We do not request CVE IDs for vulnerabilities from client assessments. Whether and how a CVE is requested is exclusively the client’s decision.
- No expiry: There is no time period after which assessment findings “could be published.” Confidentiality does not end.
The only people who learn about findings are the designated contacts for the engagement. After project completion, materials are deleted or returned, confidentiality persists.
Independent research: Coordinated disclosure
When we discover vulnerabilities in products or platforms through self-motivated, independent research, without client commission, we follow the coordinated vulnerability disclosure process. This is a separate context with its own rules.
Process
- Direct reporting: We contact the manufacturer through a secure channel (PGP-encrypted, via PSIRT/security team, through provided forms or security.txt).
- Complete technical documentation: The report includes reproduction steps, impact analysis, affected versions and, where appropriate, a proof of concept.
- Remediation support: We answer the manufacturer’s technical questions and help evaluate fix options.
- Verification: After remediation, we verify that the fix actually closes the original attack path.
Timelines (independent research only)
The following timelines apply exclusively to independent research findings, never to client assessments:
- 90 days until public discussion, counted from the first report to the manufacturer, unless a different agreement has been made.
- Actively exploited vulnerabilities: We shorten the deadline and notify the manufacturer immediately about the active exploitation.
- Extension: For justified need (e.g., complex architectural change), we agree to an extension, in exchange for transparent communication.
CVEs and advisories
For vulnerabilities from independent research with relevant impact, we request CVE IDs and publish technical advisories under Research. This does not apply to client assessments, see above.
How to report a vulnerability to us
If you have found a security vulnerability in a Redlings system, please report it via our contact page or by email to info@redlings.com.
What we expect from you
- Report the vulnerability directly and exclusively to us.
- Refrain from activities that could harm our systems (DoS, spam, social engineering).
- Do not access data that does not belong to you.
- Only test systems that clearly belong to us (redlings.com).
Safe Harbor
We will not pursue legal action against researchers who act in good faith and follow this policy.
Our process for incoming reports
- Acknowledgment: within 5 business days.
- Triage: within 10 business days.
- Remediation: prioritized by severity; critical vulnerabilities immediately.
Scope
redlings.com and redlings.de including all subdomains. Third-party systems (LinkedIn, YouTube etc.) are out of scope.
security.txt
Machine-readable at /.well-known/security.txt per RFC 9116.