demi
Security

Vulnerability disclosure policy

This is an English translation. The German version is authoritative.

Purpose

demi Technologies GmbH welcomes reports of security vulnerabilities in its products and services. If you have found a vulnerability, please report it to us directly, so we can fix it before anyone exploits it. This policy explains what it covers, how to report, which rules apply to good-faith security research and what you can expect from us.

Scope

This policy covers:

  • our website godemi.com
  • the demi platform at app.godemi.com
  • our interfaces and services at api.godemi.com, auth.godemi.com and mcp.godemi.com
  • our download site download.godemi.com
  • the desktop apps demi Talk and demi Meetings
  • the command-line tool demi CLI

Out of scope:

  • other godemi.com subdomains not listed above
  • third-party services we do not operate (please report vulnerabilities there directly to the provider)
  • social engineering and phishing
  • physical attacks
  • denial of service as well as load and volumetric testing
  • reports from automated scanners without a demonstrated impact

How to report

Send an email to security@godemi.com. Please include:

  • the affected product and version, or the affected URL
  • the steps to reproduce the issue
  • the impact of the vulnerability as you assess it
  • how we can reach you

You can write in German or English. Anonymous reports are accepted as well. In that case we can neither ask follow-up questions nor keep you informed, so please describe the finding as completely as possible. Please only include other people's personal data where it is needed to demonstrate the issue.

Rules for good-faith research

You may manually verify a vulnerability you come across during normal use, using your own accounts and test data and with as little intrusion as possible. You may also analyze the desktop apps demi Talk and demi Meetings and the demi CLI on your own device, as far as this serves finding and demonstrating vulnerabilities.

Please follow these rules while you do so:

  • Only access the data you need to demonstrate the vulnerability.
  • If you reach personal data or customer data, stop immediately and report the finding to us.
  • Do not modify or delete data.
  • Do not run denial-of-service attacks and do not disrupt our operations.
  • No spam, no social engineering and no phishing against our employees, customers or partners.
  • Do not keep access and do not set up persistent access, such as backdoors or additional accounts.
  • Keep the finding confidential until the vulnerability is fixed or until the date we have agreed with you.

Anything beyond this, such as active testing against our production systems like vulnerability scans or penetration tests, requires our prior express consent in text form (email is sufficient). You can request it via security@godemi.com.

Acting within this policy does not count as a breach of the platform terms of use (such as the ban on reverse engineering or on circumventing technical protection measures), as far as it is needed to find and demonstrate a vulnerability. Otherwise, the agreed platform terms of use continue to apply unchanged for customers.

What you can expect from us

  • We confirm receipt of your report within 3 business days.
  • We assess the report and keep you informed about its status.
  • We work on a fix and agree a disclosure date with you. Our target is a coordinated disclosure within 90 days of your report; if a different date is needed in an individual case, we agree it with you. This is not a commitment to a fix deadline or a particular outcome.
  • If we publish a security advisory for the vulnerability, we name you in it on request.

We may share information from your report with affected customers and, where required by law, with authorities, including before the agreed disclosure date. We only pass on your name and contact details with your consent or where required by law.

We do not run a bug bounty program. A report does not create any claim to a reward or payment.

Safe harbor

If you act in good faith and within the rules of this policy, demi Technologies GmbH will not bring civil claims against you and will not file a criminal complaint (Strafantrag).

This commitment binds only demi Technologies GmbH. It does not bind third parties, such as other providers or affected customers, and it does not replace a statutory justification. We cannot rule out prosecution by the authorities on their own initiative (for example for offences prosecuted ex officio or where there is a special public interest) or on a complaint filed by third parties.

Reporting to the BSI

You can also report a vulnerability to the German Federal Office for Information Security (BSI), anonymously if you wish. The BSI accepts reports through its online reporting form (in German).


Last updated: 15 September 2026. Contact: security@godemi.com