security-txt.eu

Privacy policy

This website sets no cookies and loads no embedded third-party services, apart from spam protection on the checker and forms. Everything we process is listed here. This English version is a translation; the German version prevails.

1. Controller

WDM Webdesign München GmbH, Deisenhofener Str. 45, 81539 München, Germany, phone +49 89 856 371 02, e-mail info@security-txt.de, represented by its managing director Marie-Anne Le Corre. We are not legally required to appoint a data protection officer; please send data protection enquiries to the address above.

2. Visiting the website, hosting and Cloudflare

When you visit this website, the web server processes technically necessary data: IP address, date and time, requested page, amount of data transferred, browser type and operating system, previously visited page (referrer). These data are stored in server log files and deleted after 14 days at the latest. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is the secure and stable operation of the website and defence against attacks.

The website is hosted in Germany by Mittwald CM Service GmbH & Co. KG, Königsberger Straße 4-6, 32339 Espelkamp. We have a data processing agreement with Mittwald under Art. 28 GDPR.

All requests pass through the content delivery network of Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare forwards requests to the web server, protects the website against attacks and processes the same technical data, in particular your IP address. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is a secure and fast website. We have a data processing agreement with Cloudflare including the EU standard contractual clauses; Cloudflare is also certified under the EU-US Data Privacy Framework.

3. security.txt generator

The generator builds the file entirely in your browser. To improve the tool and to see which websites it is used for and by whom, we log on our own server: the page visit, the first input, the chosen standard (RFC 9116 or BSI TR-03183-3), which explanations were opened, which types of errors were shown, copying or downloading the file and downloading the policy draft including its language, whether a mobile or desktop device was used, whether you use the German or English site and which page you came from (our own page or the host name of an external website). When you copy or download the file, and when you leave the page after entering something, we also store your entries: the domain (for example company.com), the contact addresses (e-mail and web addresses), the addresses of the policy, keys, acknowledgments, CSAF and hiring page, the bug bounty setting, the expiry date and the selected languages, plus how many months the file is valid and for each field whether it was filled in by you, derived automatically or left empty. When you download the policy draft we also store the company name and phone number entered. These details are meant to be published in the security.txt and the policy; if an address contains a name, it relates to a person. With each record we store the network operator you are connected through (for example your internet provider or your company) and the country, region and city that Cloudflare derives from your IP address. Your full IP address is kept only in the access log (section 4), which we delete after 30 days. Your browser assigns a random identifier that is kept only while the browser tab is open (sessionStorage); we set no cookies. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving the tool, understanding which websites and organisations it is used for, and preventing abuse. We delete these records after 24 months.

4. security.txt checker

For a check, our server fetches the file at the domain you entered and the addresses and keys linked in it. If a signature cannot be verified with those keys, we look up the key on the public key server keys.openpgp.org; only the key identifier is transmitted, nothing about you. We store the checked domain, the time, the language of the site, where the file was found, the retrieval status, the result of the signature check, the days until expiry and the types of findings (for example "expiry date missing"), plus the page from which the check was started, a random identifier of the browser tab (sessionStorage) and, as for the generator, network operator, country, region and city. We do not store the content of the file; your full IP address is kept only in the access log. We delete these records after 24 months.

To protect against abuse, spam and automated requests, we also log every request to the checker, to the generator's logging, including rejected ones: time, result and reason for rejection if any, the domain entered, your browser identifier (user agent), the referring page, your IP address, network operator, country, region and city, and a shortened hash of the IP address that changes daily. We delete this access log after 30 days. We use this hash to count how often each IP address checks; the counters are deleted after a short time. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is operating and improving the tool and preventing abuse.

5. Spam protection with Cloudflare Turnstile

On the checker we use Cloudflare Turnstile by Cloudflare, Inc., 101 Townsend St., San Francisco, CA 94107, USA. Turnstile is loaded only on this page, checks in the browser whether the input comes from a human and processes in particular your IP address and technical characteristics of browser and device; a task to click appears only in case of doubt. According to Cloudflare, Turnstile sets no cookies. A transfer to the USA is possible; Cloudflare is certified under the EU-US Data Privacy Framework and we have a data processing agreement with Cloudflare. More information: Cloudflare privacy policy. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is protection against spam and abuse.

6. Reporting vulnerabilities

You can report security issues to us via the report form and the addresses psirt@ and csirt@security-txt.de. We process the content of your report and, only if you provide them, your name or alias and your e-mail address or phone number. We send form submissions by e-mail via Postmark to our mailbox at Mittwald; on the server we store only when a report arrived, which area it concerns and whether it was anonymous, not its content. The purpose is to review and fix the reported vulnerability and to reply to you; the legal basis is Art. 6(1)(f) GDPR (legitimate interest in the security of our services). We do not pass on your contact details to third parties without your explicit consent. We publish your name or alias in the acknowledgments only if you wish. If a reported vulnerability in our services is actively exploited, we pass the content of the report, without your contact details, to CERT-Bund at the German BSI; the legal basis is Art. 6(1)(f) GDPR. Neither audience measurement nor Turnstile runs on the reporting page. We delete the report once the process is completed and no retention obligation applies. Anonymous reports are possible.

7. Audience measurement with Plausible

To understand which pages are read and where visitors come from, we use Plausible Analytics by Plausible Insights OÜ, Västriku tn 2, 50403 Tartu, Estonia. Plausible sets no cookies and stores nothing on your device. It records the page visited, the referring website, campaign parameters in the address if any, browser, operating system, device class, the country, region and city derived from the IP address, how far and how long a page was read, and clicks on external links, downloads and form submissions (without their content). Measurement runs through our own server: your browser sends the data to our domain and our server passes them on to Plausible. Your IP address and browser identifier (user agent) are not stored; Plausible combines them with a daily changing random value into a hash to count the visits of one day and deletes the random value after 24 hours. Recognition across several days or websites is therefore not possible. Plausible stores the data on servers in the EU (Germany); we have a data processing agreement with Plausible. The legal basis is Art. 6(1)(f) GDPR; our legitimate interest is improving our offering. More information: Plausible data policy.

8. No cookies, no embedded services

This website sets no cookies. Fonts are loaded from our own server. No maps, videos, social media buttons or third-party chat services are embedded. The only exception is Cloudflare Turnstile (section 5).

9. Recipients

Your data are disclosed only to the service providers named in this policy (Mittwald, Cloudflare, Plausible, ActiveCampaign/Postmark). If a vulnerability in our services is actively exploited, the content of a report may go, without your contact details, to CERT-Bund at the German BSI (section 6). Transfers to third countries take place only by Cloudflare, by sending via Postmark to the USA, based on the EU-US Data Privacy Framework and the EU standard contractual clauses.

10. Your rights

You have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on Art. 6(1)(f) GDPR (Art. 21). Please contact the address in section 1. You also have the right to lodge a complaint with a data protection supervisory authority; the authority responsible for us is the Bavarian Data Protection Authority (Bayerisches Landesamt für Datenschutzaufsicht), Promenade 18, 91522 Ansbach, Germany.

11. Changes

We update this policy when the website or the legal situation changes. As of October 2026.