Snakken

Responsible disclosure

Found a vulnerability in a Snakken system? Report it to security@snakken.app — encrypted if you like. Good-faith research is protected under the safe harbour below.

Last updated 3 September 2026

Contact: security@snakken.app
PGP key: snakken.app/pgp.asc — fingerprint 60B1 28AD D8E3 A2C3 51C6 E94F C344 1496 848C 1E25
Machine-readable: /.well-known/security.txt (RFC 9116)

This page is the Policy: target of our security.txt, so what a scanner finds and what you read here are the same document.

How to report

Email security@snakken.app. Write in German or English, whichever is easier for you.

Tell us what you found, how to reproduce it, and what you think the impact is. A rough note beats a polished report that never gets sent — we will come back with questions if we need more. If the report contains anything sensitive, such as a working exploit or data you came across, encrypt it with our PGP key. The key is linked above and discoverable via WKD for security@snakken.app.

Please do not post about the finding publicly or contact individual team members before we have replied.

What happens next

We are a small team and would rather promise something we can keep than a number that sounds good:

  • We acknowledge your report within three working days.
  • Within ten working days you get an initial assessment: whether we could reproduce it, how we rate the severity, and a rough timeline.
  • We aim to ship a fix within 90 days and will keep you posted as it moves.

If a finding affected our users, they hear it from us first and plainly — that comes before any technical write-up. Once a fix is out we are happy to coordinate public disclosure with you, and to credit you by whatever name you prefer, or not at all.

Safe harbour

We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith and follows this policy. We consider such research authorised, including under § 202a and § 303a StGB and the EU directives that mirror them, and we will say so in writing if a third party claims otherwise.

Good faith means: you stop as soon as you have proof of the issue, you access only data that is unmistakably your own, you do not degrade the service for anyone else, and you give us a reasonable chance to fix things before telling the world.

Snakken is a location-bound social network, so a finding can put you next to other people's personal data very quickly. If that happens: stop, do not download or keep it, and tell us what you saw. We treat that as part of the report, not as a breach of this policy.

If you are unsure whether something crosses a line, ask first — we would rather answer a question than argue about it afterwards.

Scope

In scope: snakken.app and its subdomains, including engineering.snakken.app and our API and identity hosts; the Snakken apps for iOS and Android; and the infrastructure we run them on.

Out of scope: denial-of-service and volumetric testing; physical attacks; social engineering of our team or our providers; spam, harassment and content-policy issues (report those in the app, they reach the moderation queue, not this mailbox); and anything that touches another person's account or data beyond the proof described above.

Reports produced solely by an automated scanner, without a demonstrated impact, are also out of scope — as is a missing hardening header on a static page with nothing behind it.

Third-party services we merely use are not ours to authorise. Report those to the provider; if you tell us as well, we will chase it with them.

Rewards

We do not run a paid bug bounty. We are a small team and would rather promise a fast, honest process than a payout table we cannot yet honour. What you get: a real answer from an engineer, credit if you want it, and a written summary of what we changed.

← Back to the start page