Security

Responsible disclosure

Found something? Tell us. Here is how, and what we will do.

Last updated 5 August 2026

How to report

Email contact@hansalogistics.com with “Security” in the subject line.

The same address is published at /.well-known/security.txt in the format set out in RFC 9116, so an automated scanner finds it without reading this page. TO CONFIRM: decide whether a dedicated security@hansalogistics.com mailbox is worth opening — if it is, it replaces the address in security.txt as well as here

Please include:

What we will do

We do not currently run a paid bounty programme. TO CONFIRM: decide whether to offer rewards, and state the terms here if so

Staying within the policy

So that we can honour the last of those promises, please:

Scope

In scope

Out of scope

Safe harbour

If you make a good-faith effort to comply with this policy during your research, we will consider it authorised, we will not initiate or support legal action against you in respect of it, and we will say so if a third party raises the matter. If in doubt about whether something is in scope, ask first — contact@hansalogistics.com.

We can only speak for ourselves. This policy does not, and cannot, waive the rights of our hosting provider, our carriers or anyone else whose systems you might touch, and it does not authorise anything unlawful under German or your local law.