1. Short Version
I take the security of my website, software products and future apps seriously. If you discover a vulnerability in a product or service connected to AllyouneedisHarry, please report it directly and responsibly.
This page provides a public security contact, a coordinated vulnerability disclosure process, and a clear first point of contact for security reports. It is also part of my preparation for the EU Cyber Resilience Act, Regulation (EU) 2024/2847.
Last updated: 3 August 2026. This page is a security policy and transparency notice, not legal advice.
2. Report a Vulnerability
If you find a security issue in one of my apps, software products, download files, account related functions, APIs, forms, server endpoints, or on this website, please write to:
Please do not publish details of a suspected vulnerability before we had a reasonable chance to understand, fix, and communicate the issue safely.
3. What to Include
You can write in English or German. Please describe what you found as clearly as possible, including the affected product, app, page or endpoint, the steps to reproduce the issue, the possible impact, and any screenshots or short notes that help me verify it.
Please avoid sending personal data, passwords, access tokens, private keys, payment data or unrelated confidential information. If sensitive data is accidentally involved, include only the minimum necessary detail.
4. How I Handle Reports
- Receipt: I aim to acknowledge a security report within 48 hours.
- Analysis: I review the report, reproduce the issue where possible, and assess severity and affected systems.
- Fix: I prepare and publish a correction, mitigation, configuration change or update, depending on the issue.
- Communication: I keep the reporter informed when this is useful and safe.
- Thanks: If you want to be credited, I may mention your name or handle in a changelog or security note after the issue is fixed.
5. In Scope
- Security vulnerabilities in my apps
- Security issues in future software products
- Exposed data or unprotected endpoints
- Authentication or access control issues
- Security problems on this website
- Download, update or distribution risks
6. Out of Scope
- General bugs without security impact
- Feature requests
- Spam, SEO offers or marketing messages
- Social engineering
- Denial of service testing without permission
- Third party services outside my control
7. Products Covered
This policy applies to software and digital products published under the AllyouneedisHarry brand, including this website, future Windows apps, Android apps, iOS apps, web tools, downloads and related update or support channels.
For products placed on the EU market that qualify as products with digital elements, I intend to document the expected support period, provide security updates during that period where required, and maintain a vulnerability handling process throughout the relevant product lifecycle.
8. Cyber Resilience Act Readiness
The EU Cyber Resilience Act, Regulation (EU) 2024/2847, creates cybersecurity requirements for products with digital elements, including secure development, vulnerability handling, user information and conformity related obligations.
According to official EU information, the Regulation becomes fully applicable on 11 December 2027. Reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, and notification rules for conformity assessment bodies apply from 11 June 2026.
Where a legal reporting obligation applies, actively exploited vulnerabilities or severe incidents affecting a product with digital elements will be handled through the official reporting channels required by the Regulation, including the single reporting platform once applicable. In Germany, the BSI is expected to play the central market surveillance and notification role under the national implementation framework.
9. Responsible Disclosure
Please act in good faith, test only what is necessary, avoid disruption, do not access or change data that is not yours, and do not attempt persistence, extortion, public pressure or destructive testing.
I appreciate careful security research. A clear, responsible report helps protect users, products and the wider community.
10. Official References
Useful official references include the EUR-Lex text of Regulation (EU) 2024/2847, the European Commission CRA summary, and the BSI information page.
1. Kurzfassung
Ich nehme die Sicherheit meiner Website, meiner Software Produkte und künftiger Apps ernst. Wenn du eine Schwachstelle in einem Produkt oder Dienst rund um AllyouneedisHarry findest, melde sie bitte direkt und verantwortungsvoll.
Diese Seite bietet eine öffentlich erreichbare Sicherheitskontaktstelle, einen Prozess für koordinierte Schwachstellenmeldungen und einen klaren ersten Kontakt für Security Reports. Sie ist außerdem Teil meiner Vorbereitung auf den EU Cyber Resilience Act, Verordnung (EU) 2024/2847.
Stand: 3. August 2026. Diese Seite ist eine Security Policy und ein Transparenzhinweis, keine Rechtsberatung.
2. Schwachstelle melden
Wenn du ein Sicherheitsproblem in einer meiner Apps, Software Produkte, Download Dateien, kontoähnlichen Funktionen, APIs, Formularen, Server Endpunkten oder auf dieser Website entdeckst, schreib bitte an:
Bitte veröffentliche keine Details zu einer vermuteten Schwachstelle, bevor wir eine faire Chance hatten, das Problem zu verstehen, zu beheben und sicher zu kommunizieren.
3. Was in die Meldung gehört
Du kannst auf Deutsch oder Englisch schreiben. Bitte beschreibe so genau wie möglich, was du gefunden hast: betroffenes Produkt, betroffene App, Seite oder Endpunkt, Schritte zur Reproduktion, mögliche Auswirkungen und gern Screenshots oder kurze Hinweise, die bei der Prüfung helfen.
Bitte sende keine personenbezogenen Daten, Passwörter, Zugriffstoken, privaten Schlüssel, Zahlungsdaten oder fremde vertrauliche Informationen. Falls sensible Daten aus Versehen betroffen sind, beschränke die Meldung auf das wirklich notwendige Minimum.
4. Wie ich damit umgehe
- Eingang: Ich versuche, eine Sicherheitsmeldung innerhalb von 48 Stunden zu bestätigen.
- Analyse: Ich prüfe die Meldung, reproduziere das Problem soweit möglich und bewerte Schweregrad und betroffene Systeme.
- Fix: Ich erstelle und veröffentliche je nach Problem eine Korrektur, Minderung, Konfigurationsänderung oder ein Update.
- Kommunikation: Ich informiere die meldende Person, wenn das hilfreich und sicher ist.
- Danke: Wenn du genannt werden möchtest, kann ich deinen Namen oder Handle nach der Behebung im Changelog oder in einer Security Note erwähnen.
5. Dafür ist diese Meldestelle gedacht
- Sicherheitslücken in meinen Apps
- Sicherheitsprobleme in künftigen Software Produkten
- Datenlecks oder ungeschützte Endpunkte
- Authentifizierungs oder Zugriffsprobleme
- Sicherheitsprobleme auf dieser Website
- Risiken bei Downloads, Updates oder Verteilung
6. Dafür ist diese Meldestelle nicht gedacht
- Allgemeine Bugs ohne Sicherheitsauswirkung
- Feature Wünsche
- Spam, SEO Angebote oder Marketing Nachrichten
- Social Engineering
- Lasttests oder Störungstests ohne Erlaubnis
- Drittanbieter Dienste außerhalb meines Einflussbereichs
7. Erfasste Produkte
Diese Policy gilt für Software und digitale Produkte unter der Marke AllyouneedisHarry, darunter diese Website, künftige Windows Apps, Android Apps, iOS Apps, Web Tools, Downloads und zugehörige Update oder Support Kanäle.
Für Produkte, die auf dem EU Markt bereitgestellt werden und als Produkte mit digitalen Elementen einzustufen sind, beabsichtige ich, den vorgesehenen Support Zeitraum zu dokumentieren, während dieses Zeitraums erforderliche Sicherheitsupdates bereitzustellen und einen Prozess für die Behandlung von Schwachstellen über den relevanten Produktlebenszyklus hinweg zu betreiben.
8. Vorbereitung auf den Cyber Resilience Act
Der EU Cyber Resilience Act, Verordnung (EU) 2024/2847, schafft Cybersicherheitsanforderungen für Produkte mit digitalen Elementen. Dazu gehören sichere Entwicklung, Schwachstellenbehandlung, Nutzerinformationen und Pflichten rund um Konformität.
Nach offiziellen EU Informationen gilt die Verordnung vollständig ab dem 11. Dezember 2027. Meldepflichten für aktiv ausgenutzte Schwachstellen und schwere Sicherheitsvorfälle gelten ab dem 11. September 2026. Regeln zur Notifizierung von Konformitätsbewertungsstellen gelten seit dem 11. Juni 2026.
Soweit eine gesetzliche Meldepflicht greift, werden aktiv ausgenutzte Schwachstellen oder schwere Sicherheitsvorfälle, die ein Produkt mit digitalen Elementen betreffen, über die nach der Verordnung vorgesehenen offiziellen Meldewege behandelt, einschließlich der zentralen Meldeplattform, sobald diese maßgeblich ist. In Deutschland soll das BSI im nationalen Durchführungsrahmen die zentrale Rolle für Marktüberwachung und Notifizierung übernehmen.
9. Verantwortungsvolle Offenlegung
Bitte handle in guter Absicht, teste nur das Notwendige, vermeide Störungen, greife nicht auf fremde Daten zu, verändere keine fremden Daten und nutze keine Persistenz, Erpressung, öffentlichen Druck oder destruktive Tests.
Sorgfältige Sicherheitsforschung ist willkommen. Eine klare und verantwortungsvolle Meldung hilft, Nutzer, Produkte und die Gemeinschaft zu schützen.
10. Offizielle Quellen
Nützliche offizielle Quellen sind der EUR-Lex Text der Verordnung (EU) 2024/2847, die Zusammenfassung der Europäischen Kommission und die Informationsseite des BSI.