Capitality

Sicherheitsrichtlinie

Koordinierte Offenlegung von Schwachstellen. Produktrichtlinie, keine Rechtsberatung. Stand: August 2026.

Melden

Schreiben Sie an [email protected], auf Deutsch oder Englisch. Nennen Sie die betroffene Fläche (Web-Anwendung, Mandanten-Arbeitsbereich, öffentliche Website), eine Version oder ein Datum und einen Proof of Concept ohne Kundendaten.

Dieselbe Adresse steht in security.txt.

Geltungsbereich

Im Geltungsbereich. Die Capitality-Webanwendung, die öffentlichen Marketing- und Dokumentationsseiten und der Anmeldeservice, den wir betreiben.

Außerhalb. Systeme, die Sie selbst betreiben (Ihre Post, Ihre Geräte, Integrationen, die Sie konfigurieren); Probleme, die ausschließlich in unveränderter Drittanbieter-Software bestehen — bitte upstream melden und uns sagen, wenn eine ausgelieferte Fläche betroffen ist.

Bitte nicht

Was danach passiert

Wir bestätigen den Eingang, prüfen den Bericht und halten Sie auf dem Laufenden, bis ein Fix steht. Die Firmenrichtlinie der Capkrea GmbH steht auf capkrea.com/security.html.

Weitere Seiten

Security policy

Coordinated vulnerability disclosure. Product policy, not legal advice. As of August 2026.

Report a vulnerability

Write to [email protected]. German or English. Include the product surface (the web app, a tenant workspace, or a public site), a version or date, and a proof of concept that does not include customer data.

The same contact is advertised in security.txt.

Scope

In scope. The Capitality web application, the public marketing and documentation sites, and the identity service we operate for sign-in.

Out of scope. Systems you operate (your mail, your devices, integrations you configure); issues that exist only in unmodified third-party software we depend on — report those upstream, and tell us if they affect a shipped surface.

Please do not

What happens next

We acknowledge receipt, investigate, and keep you posted until a fix ships. Capkrea GmbH's company policy is at capkrea.com/security.html.

Related pages