Responsible Disclosure

Last updated: 23 August 2026

DirektSupport takes the security of its website, systems and services seriously.

If you believe you have discovered a security vulnerability affecting DirektSupport.eu or infrastructure directly operated by DOW MEDIA SRL, we appreciate responsible reports that give us a reasonable opportunity to investigate and address the issue.

How to Report a Security Issue

Security vulnerabilities affecting DirektSupport can be reported to:

help@direktsupport.eu

Please include “Security Report” in the subject line.

Your report should contain enough information for us to understand and reproduce the issue where possible.

Useful information may include:

  • affected URL, hostname or service;
  • description of the vulnerability;
  • steps required to reproduce it;
  • expected and observed behaviour;
  • potential security impact;
  • relevant screenshots;
  • relevant request or response information;
  • your contact details if you would like a reply.

Please keep the report focused on the security issue and avoid sending unnecessary personal or confidential data.

What Is In Scope?

Responsible disclosure reports may concern security vulnerabilities affecting systems directly operated by DirektSupport or DOW MEDIA SRL, including:

  • DirektSupport.eu;
  • DirektSupport customer-facing systems;
  • authentication mechanisms operated by us;
  • forms and web applications operated by us;
  • directly managed public infrastructure belonging to DirektSupport.

A vulnerability should generally demonstrate a genuine security impact rather than simply identify outdated software, configuration information or theoretical risk.

Customer Infrastructure Is Not In Scope

DirektSupport provides technical administration for infrastructure owned and controlled by its customers.

Customer servers, websites and accounts are not automatically part of the DirektSupport security testing scope.

This includes infrastructure hosted with providers such as:

  • Hetzner;
  • OVHcloud;
  • Netcup;
  • Contabo;
  • IONOS;
  • Scaleway;
  • DigitalOcean;
  • Vultr;
  • or another third-party provider.

Do not test, access or attempt to compromise customer infrastructure unless you have explicit authorisation from the owner of that system.

If you accidentally discover a vulnerability affecting a DirektSupport customer while interacting normally with our services, please report it to us without attempting further exploitation.

Third-Party Services Are Not In Scope

DirektSupport.eu may use or reference services operated by independent third parties.

Security testing should not be performed against third-party infrastructure merely because it is linked from or integrated with DirektSupport.

Examples may include:

  • hosting providers;
  • domain registrars;
  • payment providers;
  • email providers;
  • Cloudflare;
  • external software vendors.

Vulnerabilities affecting those systems should normally be reported directly to the relevant provider according to their own disclosure process.

Please Avoid Disruptive Testing

We welcome responsible security research, but testing should not interfere with the availability, confidentiality or integrity of our systems or the systems of others.

Please do not intentionally:

  • disrupt services;
  • perform denial-of-service attacks;
  • overload infrastructure;
  • destroy or alter data;
  • access customer information unnecessarily;
  • download large quantities of data;
  • access email or private communications;
  • modify production data;
  • install persistent access mechanisms;
  • send spam;
  • perform social engineering;
  • attempt physical security attacks.

If demonstrating a vulnerability requires access to sensitive information, stop once the issue has been sufficiently demonstrated and report it to us.

Personal Data

If a vulnerability exposes personal data, please minimise access to that information.

Do not:

  • download unnecessary personal data;
  • distribute it;
  • publish it;
  • use it for any unrelated purpose.

Please tell us what type of information was exposed and how the issue was discovered.

We may need to investigate the incident under our applicable data protection and security obligations.

Credentials and Authentication

If you discover:

  • exposed credentials;
  • authentication bypass;
  • leaked API credentials;
  • exposed private keys;
  • unauthorised administrative access;

please report the issue without using those credentials beyond what is reasonably necessary to establish that a security problem exists.

Do not use discovered credentials to explore unrelated systems or customer infrastructure.

Good-Faith Security Research

We appreciate researchers who:

  • act in good faith;
  • limit testing to systems they are authorised to assess;
  • minimise access to data;
  • avoid disruption;
  • report vulnerabilities privately;
  • allow reasonable time for investigation and remediation.

Where research has been conducted responsibly and within the boundaries described in this policy, our intention is to work constructively with the reporter rather than treat responsible reporting as hostile activity.

This policy does not authorise activity that would otherwise be unlawful, nor can we authorise testing against infrastructure belonging to third parties.

Public Disclosure

Please give us a reasonable opportunity to:

  • investigate the vulnerability;
  • assess its impact;
  • develop a fix;
  • deploy remediation;

before publishing technical details that could expose DirektSupport or its customers to unnecessary risk.

Where appropriate, we may coordinate disclosure timing with the reporter.

What Happens After You Report?

After receiving a useful security report, we may:

  1. review the information;
  2. attempt to reproduce the issue;
  3. assess the potential impact;
  4. implement or plan appropriate remediation;
  5. request additional technical information where necessary.

We may contact you using the details supplied in the report.

Not every report will necessarily require a response or software change.

Vulnerabilities We Are Interested In

Examples of potentially relevant reports include:

  • authentication bypass;
  • privilege escalation;
  • unauthorised administrative access;
  • SQL injection;
  • command injection;
  • remote code execution;
  • meaningful access control failures;
  • exposure of credentials or private keys;
  • significant cross-site scripting vulnerabilities;
  • security flaws exposing confidential information;
  • server-side request forgery with meaningful impact;
  • vulnerabilities allowing modification or destruction of data.

This list is illustrative rather than exhaustive.

Reports That May Not Require Action

Some reports may have little or no practical security impact.

Examples can include:

  • missing non-critical security headers;
  • version information;
  • generic automated scanner reports without demonstrated impact;
  • public information;
  • theoretical vulnerabilities without a practical attack path;
  • clickjacking on pages without sensitive actions;
  • rate-limit observations without meaningful security consequences.

We still welcome reports where the security impact is unclear, but providing a concrete explanation of the risk helps us evaluate the issue.

Automated Security Scanning

Please use automated scanners carefully.

High-volume or aggressive automated scanning may:

  • trigger security protections;
  • affect service availability;
  • generate unnecessary traffic;
  • resemble an active attack.

Large-scale vulnerability scanning, brute-force testing or load testing is not authorised by this policy.

No Bug Bounty Programme

Unless explicitly announced otherwise, DirektSupport does not operate a public bug bounty programme.

Submitting a security report does not create an entitlement to:

  • payment;
  • compensation;
  • rewards;
  • free services.

Where appropriate, we may acknowledge useful responsible reports at our discretion.

No Guarantee of a Specific Response Time

We aim to review meaningful security reports reasonably promptly.

However, this Responsible Disclosure Policy does not create:

  • a guaranteed response time;
  • a remediation SLA;
  • a contractual obligation to implement a particular fix.

The time required depends on the nature, severity and complexity of the issue.

Security Reports vs Customer Support

This disclosure channel is intended for vulnerabilities affecting DirektSupport itself.

If your own Linux server, website or WordPress installation has been compromised, please use our normal technical support process instead.

Technical support requests can also be sent to:

help@direktsupport.eu

In your message, make clear whether you are reporting:

a vulnerability in DirektSupport, or
a security incident affecting your own infrastructure.

Confidentiality

Information contained in responsible vulnerability reports is treated as security-sensitive information.

We may share relevant details internally or with technical service providers where necessary to:

  • investigate the problem;
  • remediate the vulnerability;
  • protect affected systems;
  • comply with legal obligations.

Contact

Responsible disclosure reports:

help@direktsupport.eu

Subject:

Security Report

Administrative or privacy matters:

office@direktsupport.eu

DOW MEDIA SRL
Strada Johann Heinrich Pestalozzi, Nr. 3-5
Timișoara, Romania
European Union

Trade Register: J35/3199/03.11.2004
VAT / Tax ID: RO16906010

Responsible Security

DirektSupport works with production Linux infrastructure where security and trust are important.

We appreciate responsible researchers who identify genuine security problems and give us the opportunity to address them without unnecessarily exposing customers, systems or data.

Report responsibly. Minimise impact. Give us the opportunity to fix the problem.