Reporting a vulnerability
Coordinated vulnerability disclosure policy. Last updated: 2026-07-25. The German version is the legally binding one.
1. How to reach us
Please report security vulnerabilities by email to security@air-node.net — in German or English. The address is also published in our machine-readable https://air-node.net/.well-known/security.txt (RFC 9116).
What helps us act quickly: a description of the vulnerability, the affected component (website, app/API, device or firmware), step-by-step reproduction instructions, the impact you believe it has, and logs or screenshots if you have them. Please do not include other people’s personal data.
2. Scope
In scope: the publicly reachable services we operate under air-node.net and its subdomains, the connection between AirNode devices and the platform, and the AirNode device firmware.
Out of scope: our service providers’ own systems (our privacy policy names the providers we use) — please report those to them directly; denial-of-service and load testing; physical attacks; social engineering against us or our providers; spam or bulk-registration attempts; and findings with no security impact (for example a missing header with no demonstrable exploitability).
3. What you can expect from us
We acknowledge your report within five working days and send you our initial assessment within ten working days, then keep you posted as we remediate. AirNode is run by one person, so please expect prioritisation to reflect that.
We will credit you as the finder once the issue is fixed, if you would like that. We do not pay rewards (there is no bug-bounty programme).
4. Safe harbour for good-faith research
If you follow this policy, we consider your research authorised and in good faith, and we will not pursue legal action against you for it. Please stay within these limits: use only your own accounts and your own devices; do not access other users’ data or download anything beyond what is needed to demonstrate the issue; do not disrupt the service (no load testing, no deletions, no changes to anyone else’s data); and report promptly and keep the finding confidential until it is fixed.
This assurance can only cover us — not third parties whose systems you touch, and not conduct that mandatory law prohibits regardless.
5. Coordinated disclosure
We ask for 90 days from your report before you publish details; for vulnerabilities already being exploited we will agree a shorter timeline with you. If we finish sooner, we will clear publication sooner.
Where a vulnerability involves personal data, our Art. 33/34 GDPR obligations apply independently: we notify the supervisory authority and affected individuals to the extent the law requires.