Legal
Report a vulnerability
How to report security issues in our services and in gh0stcli.
Reporting Security Vulnerabilities
As of: 14 September 2026
We take reports of security vulnerabilities seriously and thank everyone who informs us responsibly. This policy describes how you report a vulnerability, what you can expect from us and which rules apply to security research on our services.
1. Scope
- the website gh0stservice.com and the customer portal
- the application programming interfaces and the gh0stcloud platform
- sign-in via Keycloak
- the command-line tool gh0stcli in all published versions
Not covered are applications that our customers operate on gh0stcloud. Please report vulnerabilities in such applications to the respective operator. If an attack or misuse originates from such an application, please use our notice procedure.
2. How to report a vulnerability
Send your report to info@gh0stservice.com with the subject "Security". The following information is helpful:
- affected system, address or version of gh0stcli
- description of the vulnerability and its potential impact
- steps to reproduce
- your contact details for follow-up questions, or a pseudonym if you prefer
If you would like to transmit information in encrypted form, send us a short message; we will then agree on a secure channel.
3. What you can expect from us
- acknowledgement of receipt within 3 business days
- an initial assessment and ongoing updates on the status
- remediation within a period appropriate to the severity of the vulnerability
- coordinated disclosure: we ask you to publish details only after remediation, but no later than after 90 days, unless we agree otherwise
- on request, acknowledgement in our remediation notices
4. Rules for security research
If you act in good faith and in accordance with these rules, we will not take legal action against you:
- Access data only to the extent strictly necessary to demonstrate the vulnerability, and delete it afterwards.
- Do not access data or applications of other customers, and do not modify any data.
- Do not carry out denial-of-service attacks, load tests or spam attempts.
- Refrain from social engineering, phishing and physical attacks.
- Do not exploit a vulnerability beyond demonstrating it, and do not disclose it to third parties.
5. Obligations under the Cyber Resilience Act for gh0stcli
As the manufacturer of gh0stcli, we comply with the obligations of Regulation (EU) 2024/2847 (Cyber Resilience Act):
- We report actively exploited vulnerabilities and severe security incidents affecting gh0stcli within the prescribed deadlines via the single reporting platform to the Bundesamt für Sicherheit in der Informationstechnik (BSI, German Federal Office for Information Security) and the European Union Agency for Cybersecurity (ENISA).
- We inform users about vulnerabilities and available security updates in the release notes and, where necessary, on our status page.
- We provide security updates for the current version of gh0stcli. Published versions are cryptographically signed.
6. Machine-readable contact information
Our contact information for security reports is also available at /.well-known/security.txt.