ALPINELAYER · Swiss Cloud InfrastructureSales: sales@alpinelayer.ch · Support: support@alpinelayer.ch
Legal & Policies

Vulnerability Disclosure Policy

Rules for responsible security research and reporting.

Version 1.0Last updated 2 September 2026English

1. Good-faith research

AlpineLayer welcomes responsible vulnerability reports. Researchers acting in good faith, minimizing harm and following this policy will not be treated as malicious solely for authorized research described here, to the extent AlpineLayer can make that commitment under applicable law.

2. Allowed testing

  • Testing your own account and resources.
  • Non-destructive testing of public AlpineLayer applications without accessing another user’s data.
  • Proof-of-concept activity limited to what is necessary to show the issue.

3. Prohibited activity

  • Accessing, copying, modifying or deleting other users’ data.
  • Social engineering employees or customers.
  • Physical intrusion, denial-of-service or traffic flooding.
  • Persistent access, malware deployment or destructive testing.
  • Public disclosure before AlpineLayer has had a reasonable chance to investigate and remediate.

4. Report

Send reports to security@alpinelayer.ch with the asset, issue, reproduction steps, impact and contact information. A PGP key can be added to security.txt later.

5. Response

AlpineLayer will acknowledge credible reports, investigate severity and coordinate remediation where practical. No bug-bounty payment is promised unless a formal program is published.