โ† Back to home

Vulnerability disclosure

Last updated: August 2026

If you believe you have found a security issue in ComicStyles, please tell us. Reports in English or German are welcome.

How to report

Email security@comicstyles.com. Include enough detail to reproduce the issue (steps, affected URL, and a proof of concept if you have one). Please do not include other people's personal data beyond what is needed to show the bug.

Scope

In scope: this website and its API โ€” authentication, sessions, CSRF, account and billing flows, and stored content.

Out of scope:

  • Third-party services we call (image and text providers, Mollie, Cloudflare, MongoDB hosting).
  • Volumetric denial of service, spam, or social engineering.
  • Findings that require a compromised device, physical access, or a victim who already clicked through a warning.

What we ask

  • Give us a reasonable chance to fix the issue before you publish it. We will try to respond within a few days.
  • Do not access, modify, or delete other people's data beyond a minimal proof of concept.
  • Do not use an automated scanner against production in a way that degrades the service.

There is no bug-bounty programme. Good-faith research that follows this policy is welcome, and we will not pursue legal action against researchers who stay in scope.

security.txt ยท Impressum