Report security holes straight to us.

If you find a vulnerability on this website or in a system we run, write to us. We look into every report and answer you. We do not pay bug bounties.

Three steps so we can close the hole quickly.

  1. 01

    Describe

    What you found, where, and how it can be reproduced.

  2. 02

    Send

    To legal@gl-digital.net, with requests and screenshots if you like, but without other people's data.

  3. 03

    Give us time

    Publish nothing before the hole is closed. We tell you when it is.

Test, yes. Harm, no.

  • Only as far as needed

    Do not access other people's data, change or delete nothing, and stop once the hole is shown.

  • No load tests

    No denial of service, no spam and no automated mass requests.

  • No bounties

    We pay no bug bounty. Every report is read and answered.

The contact is in security.txt too.

At /.well-known/security.txt you find the same details following RFC 9116, for tools and researchers who look there first.