Security
Responsible disclosure
Found something? Tell us. Here is how, and what we will do.
Last updated 5 August 2026
How to report
Email contact@hansalogistics.com with “Security” in the subject line.
The same address is published at /.well-known/security.txt in the format set out in RFC 9116, so an automated scanner finds it without reading this page. TO CONFIRM: decide whether a dedicated security@hansalogistics.com mailbox is worth opening — if it is, it replaces the address in security.txt as well as here
Please include:
- What you found, and where — a URL or a specific request.
- How to reproduce it, step by step.
- What an attacker could actually do with it.
- Anything you need us to know to reproduce it safely.
- How you would like to be credited, if at all.
What we will do
- Acknowledge within three working days. A person, not an autoresponder.
- Assess and tell you what we found, normally within ten working days.
- Fix what needs fixing, and tell you when it is done.
- Not pursue you — legally or otherwise — for good-faith research that stays within this policy.
- Credit you if you want it, once the issue is resolved.
We do not currently run a paid bounty programme. TO CONFIRM: decide whether to offer rewards, and state the terms here if so
Staying within the policy
So that we can honour the last of those promises, please:
- Give us a reasonable opportunity to fix the issue before disclosing it publicly — 90 days is the norm, and we will usually be much faster.
- Use only your own test data. Do not access, modify, download or retain anyone else’s data — if you encounter personal data, stop and tell us.
- Do not degrade the service: no denial of service, no volumetric or brute-force testing, no spam through the enquiry form.
- Do not use social engineering, phishing or physical intrusion against our staff, our offices or our suppliers.
- Do not test systems that are not ours. Our carriers, agents and the regulators we link to are out of scope entirely.
Scope
In scope
- intl.hansalogistics.com and everything served from it.
- The enquiry form and the lane planner.
- Anything that exposes personal data, allows content to be modified, or allows script to run in another visitor’s browser.
Out of scope
- Findings from automated scanners without a demonstrated, exploitable impact.
- Missing security headers, cookie flags or TLS configuration preferences with no practical exploit — the site sets no cookies at all.
- Rate limiting on a static site, and self-XSS.
- Best-practice reports such as missing SPF/DMARC alignment on non-mail domains, absent a real attack path.
- Vulnerabilities in third-party regulator websites we link to.
- Social engineering, physical security and denial of service.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, we will not initiate or support legal action against you in respect of it, and we will say so if a third party raises the matter. If in doubt about whether something is in scope, ask first — contact@hansalogistics.com.
One caveat
We can only speak for ourselves. This policy does not, and cannot, waive the rights of our hosting provider, our carriers or anyone else whose systems you might touch, and it does not authorise anything unlawful under German or your local law.