
Found a security vulnerability in SecureSafe or another DSwiss system? This policy explains what’s in scope, how to report it to us, the response and remediation commitments we make, and the safe harbor we offer security researchers acting in good faith.
Version 1.0, from 08.09.2026
Responsible Disclosure Policy
Security is at the core of everything we do at DSwiss AG. Despite our best efforts, vulnerabilities may still exist. If you have discovered a security vulnerability in one of our systems, we appreciate your help in disclosing it to us responsibly. We are committed to working with security researchers to verify and address reported issues.
Scope
This policy applies to the following systems operated by DSwiss AG:
Systems operated by third parties are out of scope, even if linked from our services.
Out of scope
The following are not considered qualifying vulnerabilities and should not be tested:
How to report
Please report vulnerabilities to security@dswiss.com.
Include where possible:
You may report anonymously; however, we cannot keep you informed of progress without contact details.
Rules of engagement
When investigating a potential vulnerability, we ask that you:
Our commitments
Safe harbor
DSwiss will not initiate legal action against security researchers who, in good faith:
We consider research conducted in accordance with this policy to be authorized and welcome.
Recognition
We do not currently operate a paid bug bounty program. With your consent, we are happy to acknowledge meaningful contributions.
Our vulnerability handling is aligned with ISO/IEC 29147 (vulnerability disclosure) and ISO/IEC 30111 (vulnerability handling processes) and forms part of our ISO/IEC 27001-certified information security management system. Reports may also be coordinated through the Swiss National Cyber Security Centre (NCSC) coordinated vulnerability disclosure program.