AssetObserve
Sign in Start free
Legal

Vulnerability disclosure policy

Last updated: 13 August 2026

Reporting a vulnerability

If you believe you have found a security vulnerability in the AssetObserve service, please report it to contact@assetobserve.com. This page is the policy referenced by our security.txt record at /.well-known/security.txt.

Please include enough detail for us to reproduce the issue: the affected URL or component, the steps you took, what you observed, and what you expected. A proof of concept, request log, or screenshot helps. Let us know if you would like to be credited.

What we commit to

  • We acknowledge a report within five working days.
  • We tell you our assessment of the severity and our intended remediation timeline once we have reproduced the issue.
  • We keep you informed while we work on a fix, and we tell you when it is deployed.
  • We do not pursue legal action against a finder who follows this policy in good faith.

We do not currently operate a paid bug bounty. Credit in our release notes is available on request.

Scope

In scope: the AssetObserve web application, its public API, its agent ingest endpoints, and the customer-side agent we distribute.

Out of scope:

  • Findings against a customer workspace that is not your own, or against systems belonging to a customer
  • Denial-of-service testing, load testing, and any test that degrades the service for other users
  • Social engineering, phishing, or physical attacks against our staff or providers
  • Reports produced only by an automated scanner, with no demonstrated impact
  • Missing hardening headers or configuration recommendations with no demonstrated exploit path
  • Vulnerabilities in third-party services we consume, which should be reported to that provider

Testing guidelines

Please test only against your own account or workspace, or against the public demo environment. Use the minimum interaction needed to demonstrate the issue. Do not access, modify, delete, or retain personal data belonging to anyone else; if you encounter such data, stop and tell us in the report. Do not publish details of an unfixed issue.

Our own product

AssetObserve is a read-only assessment tool by design: it does not exploit, brute-force, modify, or disable the systems it inventories, and must only be pointed at systems the operator is authorized to assess. A report that AssetObserve can be used against an unauthorized network describes the operator's misuse rather than a defect, but we do want to hear about anything that lets one workspace observe another's data.

Placeholder notice

Confirm the acknowledgement window, the remediation timelines, the safe-harbour wording, and whether a demo environment is offered for testing, and have the safe-harbour paragraph reviewed by legal counsel, before this policy is published.

Contact: contact@assetobserve.com

AssetObserve

AssetObserve helps IT teams and service providers document authorized internal infrastructure, scanner coverage, risk findings and reports from one SaaS workspace.

Platform Platform Capabilities Plans
Compliance NIS2 readiness BSI IT-Grundschutz
Company Help FAQ Contact Support Service status
Legal Impressum Datenschutz AGB Cookie Richtlinie Data processing agreement Security measures Subprocessors Service level agreement Vulnerability disclosure Accessibility
AssetObserve
contact@assetobserve.com