Security reporting
If you believe you found a security vulnerability in AloxBook, an official installer, or the update service, email security@aloxbook.com. Please do not publish the details until you have allowed a reasonable time for investigation.
What to include
- The affected AloxBook version, operating system, and installation source
- A concise description of the issue and its possible impact
- Exact reproduction steps or a minimal proof of concept that contains no personal financial data
- Whether you believe the issue has already been disclosed or exploited
Do not send passwords, .aloxbook files, bank statements, or unredacted financial screenshots.
Handling
Support and security reports are reviewed on a best-effort basis. No response or resolution is guaranteed, no response or correction time is promised, and there is no maintenance commitment. Messages are accepted in English, German, French, Spanish, and Italian; replies may use translation assistance.
Research boundaries
Only test systems and data you own or are explicitly authorized to test. Do not disrupt services, use social engineering, access another person's data, or retain data encountered accidentally. Stop and report if you unexpectedly gain access to data or systems.
This page does not authorize activity that would otherwise be unlawful or outside your permission, and it does not create a bug bounty, reward, employment, or support commitment.
Other problems
Installation problems, usage questions, and ordinary bugs belong on the Support page.
Publisher
AloxBook is published and licensed by Alois Hartl. Full legal details are available in the Imprint.