Report a security vulnerability
Last updated: 10 October 2026 · Deutsche Fassung
The security of our customers' data and of their guests matters to us. If you believe you have found a security vulnerability in HelpYa, we would like to hear from you.
How to report
Please email kontakt@helpya.com with the subject “Security vulnerability”. Helpful details:
- a short description of the vulnerability and its possible impact,
- the affected address or feature,
- the steps needed to reproduce it (screenshots welcome),
- how we can reach you with questions.
We reply in German or English.
Please keep it confidential
Please do not share the vulnerability with third parties or publish it until we have fixed it or agreed a date with you.
What you can expect from us
- We acknowledge receipt of your report within 3 business days.
- We look into the report, keep you informed of progress and tell you when the vulnerability has been fixed.
- If you wish, we will credit you as the finder once it is fixed. We will not share your name without your consent.
We do not run a reward programme (bug bounty).
Safe harbour for good-faith research
If you look for vulnerabilities in good faith and follow the rules below, you need not fear legal action from us. In that case we will not file a criminal complaint or bring claims against you. The rules:
- Access only as much data as is needed to demonstrate the vulnerability. If you see third-party data, stop immediately, do not keep it and let us know.
- Do not modify or delete data and do not disrupt the service – in particular no denial-of-service attacks, no spam and no automated mass requests.
- No attacks on people (e.g. phishing or deceiving staff or customers) and no physical attacks.
- Use your own test accounts wherever possible rather than other people's accounts.
- Share the vulnerability confidentially and only with us.
This commitment covers systems operated by HelpYa itself. Systems of other providers (e.g. payment services, push services, hosting) are subject to their own rules. It binds only us and cannot waive the rights of third parties.
Responsible
Information security is the responsibility of the management of FFM&M RE GmbH, Sybelstraße 31, 10629 Berlin, Germany. Machine-readable: /.well-known/security.txt.