Sign in Open console

Vulnerability Disclosure Policy#

This policy gives external security researchers a safe, predictable way to report vulnerabilities they find in icons (icon0.eu). We welcome these reports and treat them as valuable input to our security. icons is operated by botBrains GmbH; a report received here enters the same incident management process as any other security event, following the botBrains Incident Management Policy. The canonical company-wide policy lives at docs.botbrains.io/trust/policies/responsible-disclosure-policy; this page applies it to icon0.eu.

How to report#

Send vulnerability reports to security@icon0.eu. A good report includes a description of the issue, the affected URL, endpoint, or component, the steps to reproduce it, and any proof-of-concept material. You may report in English or German. Please report in private and give us a reasonable opportunity to fix the issue before disclosing it publicly.

Scope#

In scope is everything served under icon0.eu: the landing page and console, the icon endpoints (/domain/*, /t/*), the tenant API (/api/v1/*), and the served documentation and legal pages. Of particular interest: server-side request forgery through the icon fetcher, cache poisoning, rate-limit bypasses, and anything that would make the service log or retain visitor data it promises not to.

Out of scope:

Out of scope Reason
Third-party services and our subprocessors Report these to the provider directly - see the Subprocessor list.
Findings that require physical access, social engineering, or phishing of personnel Not a technical vulnerability in our systems.
Volumetric denial-of-service and automated scanner output without demonstrated impact Low signal and potentially disruptive; note the service is deliberately rate-limited.
The content of third-party favicons we cache and serve The artwork belongs to the respective site; we serve it as published.

Safe harbour#

botBrains won't pursue or support legal action against researchers who act in good faith under this policy. Acting in good faith means you stay within the scope set out here, make a genuine effort to avoid privacy violations, data destruction, and service disruption, only interact with accounts you own or have explicit permission to test, don't access, modify, or retain data beyond the minimum needed to demonstrate the issue, and give us reasonable time to remediate before any public disclosure. If you accidentally encounter personal or tenant data, stop, don't save or share it, and tell us in your report.

No bounty#

icons doesn't operate a paid bug bounty programme and doesn't offer monetary rewards for reports. We will acknowledge your report, keep you informed, and credit you for a valid finding if you would like that. We state this plainly so expectations are clear.

What to expect from us#

Stage Our commitment
Acknowledgement We aim to confirm receipt of your report within a few business days.
Triage Severity is assessed under the Incident Management Policy.
Remediation We fix valid findings on a timeline driven by severity, prioritizing validated, exploitable issues.
Closure We let you know when we resolve the issue.