KORTHEXkorthex.io

Security

Reporting a vulnerability

Written and maintained by Hendrik Schneider · Last reviewed · How we check this

Korthex is a cryptography scanner, so a flaw in it is a flaw in something people use to judge their own security. Reports are welcome, including ones that show the scanner is wrong. This page is the policy referenced from /.well-known/security.txt.

How to report

  • Email contact@flowencehq.com with 'security' in the subject line. Reports are read in German and English.
  • Include the affected component and version, what you observed, and the smallest reproduction you have. A scan artifact is useful; a scan artifact from someone else's codebase is not - do not send data you are not entitled to share.
  • The machine-readable contact record is at /.well-known/security.txt per RFC 9116.
  • Please give us the chance to ship a fix before publishing. There is no bounty programme; there is an acknowledgement, and a named credit in the changelog if you want one.

Published response targets

These are the targets from the Korthex Service Level Agreement, section 4.4. The clock starts when the vulnerability is verified, not when the mail arrives.

Target time to a patch or a documented mitigation, by CVSS severity.
SeverityEnterpriseBusiness
Critical (CVSS 9.0-10.0)72 hours7 days
High (CVSS 7.0-8.9)7 days14 days
Medium (CVSS 4.0-6.9)30 days45 days
Low (CVSS 0.1-3.9)next regular release, at the latest within 180 dayssame

Scope

  • In scope: the Korthex desktop application, the command-line interface, the SDKs, the license portal, and this website.
  • In scope and specifically wanted: a case where the scanner reports a finding that is not real, or misses one that is. Detection correctness is a security property of this product, not a quality metric.
  • Out of scope: findings that require a compromised host, social engineering, volumetric denial of service, and reports generated by a scanner without a demonstrated impact.
  • Out of scope: the third-party standards Korthex grades against. A disagreement with BSI TR-02102 is a matter for the BSI.

Regulatory reporting

Where a vulnerability in Korthex is being actively exploited, or a severe incident affects the security of the product, the provider submits an early warning to the coordinating CSIRT and to ENISA within 24 hours of becoming aware, followed by a notification within 72 hours. Affected customers are informed without undue delay at the address held in their account. The full text is in the SLA.

Frequently asked questions

How do I report a security vulnerability in Korthex?

Email contact@flowencehq.com with 'security' in the subject, including the affected component, version and a minimal reproduction. The machine-readable contact record is at https://korthex.io/.well-known/security.txt.

Does Korthex pay a bug bounty?

No. There is no bounty programme. Valid reports receive an acknowledgement and, if you want one, a named credit in the changelog.

How quickly does Korthex patch a critical vulnerability?

The published target is 72 hours for Enterprise and 7 days for Business at CVSS 9.0-10.0, measured from verification of the vulnerability. The full severity table is in section 4.4 of the SLA.