HDN · Responsible disclosure

Report a security vulnerability

Report vulnerabilities affecting HDN websites and our own products. Share findings confidentially and coordinate responsible disclosure.

Deutsche Version

Choose the right contact

HDN websites and HDN’s own products: Report potential vulnerabilities to security@hd-n.at, using the subject “Schwachstelle” (HDN security report). Clicking the email address prefills this subject to support consistent routing.

PaulinAI and Paulina Hub: Contact security@paulinai.dev. See the PaulinAI security policy for details.

A security incident at your company: Use your agreed support or emergency contact or the HDN ticket system. This page does not replace an agreed emergency procedure or promise round-the-clock availability.

What to include

  • Affected website, URL or product version.
  • A description and reproducible steps.
  • Potential impact and any observed exploitation.
  • Contact details if you would like a response.

Do not send passwords, access keys or personal customer data. Please arrange a suitable transfer channel before sharing sensitive technical evidence.

Review and coordinated disclosure

We review reports and coordinate questions, next steps and updates with you. Response and remediation times depend on the individual case; this page does not promise fixed deadlines.

Please coordinate publication of technical details with us so that protective measures can be prepared and affected users informed. We will credit you only with your consent.

This reporting channel does not authorise unauthorised access, extraction of third-party data or disruptive testing. Test only systems for which you have explicit permission. Findings affecting customer systems must follow the process agreed with that customer.

Other enquiries and responsible company

For consulting or a commissioned cybersecurity check, use our contact page. Telephone: +43 5675 43295.

High-Definition Development & Networks GmbH · Kappl 14, 6677 Schattwald, Austria.

Legal notice · Privacy · Machine-readable security contact