We build a platform where people meet in real life — the trust our members place in us extends to how we handle their data. If you believe you have found a security vulnerability in a Conpeo system, we want to hear from you, and we will treat your report with respect and urgency. There is currently no bug bounty program; we offer sincere thanks and, if you wish, public acknowledgement.
1.Scope
In scope: conpeo.eu (website) · studio.conpeo.app (operator web app) · the Conpeo iOS app · Conpeo-operated APIs and backend services behind these surfaces.
Out of scope: systems of our service providers (Supabase, Stripe, PostHog, Vercel, Apple, Google — please report to them directly under their own programs) · social engineering, phishing or physical attacks against Conpeo, our members or hosts · denial-of-service and volumetric testing · spam · findings without security impact (e.g., missing best-practice headers without a demonstrated exploit, clickjacking on pages without sensitive actions, software version disclosure alone).
2.How to report
Email security@conpeo.eu with: a description of the issue and its impact, affected URL/endpoint/app version, reproduction steps or proof of concept, and any relevant logs or screenshots. German or English — both welcome. Please do not open public issues or social posts before we have resolved the matter (see coordinated disclosure below).
3.What we commit to
We will acknowledge your report within 5 business days, keep you informed about our progress, prioritize remediation by severity, and tell you when the issue is fixed. We are a very small team; we ask for your patience and promise honesty about timelines in return.
4.Safe harbor
If you make a good-faith effort to comply with this policy — staying in scope, avoiding privacy violations and service disruption, and reporting promptly — we will consider your research authorized, will not initiate criminal complaints and will not pursue civil claims against you for it, to the extent legally permissible. If you inadvertently access personal data: stop, do not copy or share it beyond the minimum needed to demonstrate the issue, report immediately, and delete it after reporting. If a third party takes legal action against you for activities conducted in accordance with this policy, we will make it known that your actions were authorized by us.
5.Coordinated disclosure
Please give us 90 days from acknowledgement before any public disclosure; we are happy to coordinate an earlier joint disclosure once a fix is deployed. We will credit you by name or handle if you wish — or keep you anonymous.
(B-DE) Kurzfassung auf Deutsch
Geltungsbereich: conpeo.eu, studio.conpeo.app, die Conpeo-iOS-App sowie die dahinterliegenden, von Conpeo betriebenen APIs. Nicht umfasst: Systeme unserer Dienstleister (bitte direkt dort melden), Social Engineering, physische Angriffe, DoS-/Lasttests, Spam, Befunde ohne Sicherheitsauswirkung.
Meldung: per E-Mail an security@conpeo.eu — Beschreibung, betroffene Stelle, Reproduktionsschritte/PoC; Deutsch oder Englisch. Unsere Zusage: Eingangsbestätigung innerhalb von 5 Werktagen, laufende Information, Behebung nach Schweregrad priorisiert. Kein Bug-Bounty; auf Wunsch öffentliche Danksagung.
Safe Harbor: Gutgläubige Sicherheitsforschung im Rahmen dieser Richtlinie betrachten wir als autorisiert; wir erstatten insoweit keine Strafanzeige und machen keine zivilrechtlichen Ansprüche geltend, soweit gesetzlich zulässig. Stoßen Sie unbeabsichtigt auf personenbezogene Daten: anhalten, nichts kopieren oder weitergeben, sofort melden, danach löschen.
Koordinierte Offenlegung: bitte 90 Tage ab Eingangsbestätigung vor jeder Veröffentlichung; frühere gemeinsame Offenlegung nach Fix jederzeit möglich.