Platform
Platform
  • Secure Data Platform (Business)
  • Secure Data Platform (Individual)
Modules
  • Pass
  • File
  • Postbox
  • Exchange
Ready to get started?
Sign up now
Solutions
By segment
  • SMB
  • Mid market
  • Enterprise
By industry
  • Banks
  • Fiduciaries
  • Insurances
  • Wealth management
  • Defense
 
  • Utility providers
  • Legal
  • Public Administration
By Use Case
  • Mortgage application
  • Customer mailbox in
    e-Banking
Ready to get started?
Sign up now
Pricing
Company
  • About Us
  • Partner
  • News
  • Career
  • Sustainability
Ready to get started?
Sign up now
Resources
page group one
  • Case studies
  • Blog
  • Release Notes
page group two
  • Certifications
  • Security
  • Help center
Featured from Blog

What digital sovereignty is, and why it matters more in 2026 than ever before

Digital sovereignty means real control over data, infrastructure, and access. What it involves under GDPR, revDSG, DORA and NIS-2, and how SecureSafe delivers it.

Read more

When your AI leaves the country without telling you

Microsoft Copilot's flex routing can send EU prompts abroad under load. What it means for FINMA, DORA and revDSG, and how to switch it off this week.

Read more
All Blogs
For Individuals
Book a demo
For individuals
Login
SecureSafe Classic
Pre - June 2025
Login
SecureSafe Next
Post - June 2025
Login
Book a demo
Login
SecureSafe Classic
Pre - June 2025
Login
SecureSafe Next
Post - June 2025
Login

Responsible Disclosure Policy

Found a security vulnerability in SecureSafe or another DSwiss system? This policy explains what’s in scope, how to report it to us, the response and remediation commitments we make, and the safe harbor we offer security researchers acting in good faith.

  • Imprint
  • Legal Definitions (Next)
  • General Terms and Conditions (Next)
  • Data Processing Agreement (Next)
  • End User Terms (Next)
  • End User Terms (Classic)
  • Privacy Policy (All)
Contact Us

Version 1.0, from 08.09.2026

Responsible Disclosure Policy

Security is at the core of everything we do at DSwiss AG. Despite our best efforts, vulnerabilities may still exist. If you have discovered a security vulnerability in one of our systems, we appreciate your help in disclosing it to us responsibly. We are committed to working with security researchers to verify and address reported issues.

Scope

This policy applies to the following systems operated by DSwiss AG:

  • www.securesafe.com and the SecureSafe web application
  • SecureSafe mobile applications (iOS and Android)
  • SecureSafe browser extension
  • SecureSafe desktop application

Systems operated by third parties are out of scope, even if linked from our services.

Out of scope

The following are not considered qualifying vulnerabilities and should not be tested:

  • Denial-of-service (DoS/DDoS) attacks or resource-exhaustion testing
  • Social engineering, phishing, or physical attacks against DSwiss employees, offices, or data centers
  • Spam, SPF/DKIM/DMARC configuration opinions without demonstrated impact
  • Vulnerabilities requiring outdated browsers or platforms
  • Clickjacking on pages with no sensitive actions
  • Automated scanning that generates significant traffic
  • Vulnerabilities in third-party services

How to report

Please report vulnerabilities to security@dswiss.com.

Include where possible:

  • A description of the vulnerability and its potential impact
  • Steps to reproduce (proof of concept, screenshots, or scripts)
  • The affected system, URL, or app version
  • Your contact details for follow-up questions

You may report anonymously; however, we cannot keep you informed of progress without contact details.

Rules of engagement

When investigating a potential vulnerability, we ask that you:

  • Do not access, modify, or delete data belonging to other users. If a vulnerability exposes data that is not yours, stop immediately and report it.
  • Limit testing to the minimum necessary to demonstrate the vulnerability (proof of concept only, no data exfiltration).
  • Do not disrupt our services or degrade the experience of our users.
  • Do not use the vulnerability for your own or a third party's benefit.
  • Give us reasonable time to remediate before any public disclosure (see coordinated disclosure below).

Our commitments

  • We will acknowledge your report within 5 business days.
  • We will provide an initial assessment and keep you informed about remediation progress.
  • We remediate confirmed vulnerabilities in line with our internal patch management standard. Critical vulnerabilities in production systems are addressed within 48 hours of a fix being available.
  • We practice coordinated disclosure: we ask you to refrain from public disclosure for 90 days from your report or until a fix is deployed, whichever comes first. We are happy to agree on a coordinated publication with you.

Safe harbor

DSwiss will not initiate legal action against security researchers who, in good faith:

  • comply with this policy and the rules of engagement above,
  • report their findings promptly and exclusively to us, and
  • do not compromise the privacy or safety of our customers or the availability of our services.

We consider research conducted in accordance with this policy to be authorized and welcome.

Recognition

We do not currently operate a paid bug bounty program. With your consent, we are happy to acknowledge meaningful contributions.

Our vulnerability handling is aligned with ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling processes) and forms part of our ISO/IEC 27001-certified information security management system. Reports may also be coordinated through the Swiss National Cyber Security Centre (NCSC) coordinated vulnerability disclosure program.

Footer

SecureSafe Logomark

Your data is more than just files: It’s a responsibility.

At SecureSafe, we treat your data with the same care and diligence you put into creating it. Ready to secure your critical data?

Book your demo
Find the right plan

Platform

Secure Data Platform (Business)
Secure Data Platform (Individual)

Pricing

Pricing (Business)
Pricing (Individual)

Modules

FOR B2B

Pass
File
Exchange
Postbox

For Individual

Pass
File

Resources

Case studies
Blog
Certifications
Security
Release notes
Help center

Downloads

Mobile

iOS
Android

Browser extension

Chrome
Safari
Edge
Firefox

Desktop

macOS (Apple Silicon)
macOS (Intel)
Windows

Company

About Us
Partner
News
Career
Sustainability
Contact us
en
en
de
fr
it

Your Data. Secure. Proven.

Address:

DSwiss AG
Flurstrasse 64
CH-8048 Zurich
Switzerland

  • ISO 27001 certified badgeSwiss made software badgemyclimate verified badge
© 2026 DSwiss. All Rights Reserved.
Imprint
Privacy Policy
Legals
Cookies Settings
SecureSafe Logo