Security
Found a weakness in TEELS? Tell us. We would much rather hear it from you than read about it later.
How to report
Email security@teels.ch, in German or English.
Philipp Häfelfinger (CTO) reads that mailbox, with Roman Marty (CEO) as deputy. The address is also
published as a machine-readable security.txt under
RFC 9116.
Useful in a report: what you found, how to reproduce it, and what an attacker could do with it. A rough description of a real problem is worth more to us than a polished description of a theoretical one — send what you have.
What we promise
- Within 3 working days we acknowledge your report.
- Within 10 working days you get a first substantive answer.
- After that we keep you posted at each material step until the case is closed.
Working days are Swiss (Canton of Zurich) business days.
We do not run a bug bounty and we do not pay for reports. If you would like credit for a finding, say so and we will name you in the release notes when the fix ships.
Safe harbour
Research done in good faith is welcome, and we will not pursue legal action or involve law enforcement over it. In good faith means:
- You only touch your own account and data, or a test organisation you created yourself.
- You do not access, alter or copy anyone else’s data. If you reach another customer’s data by accident, stop, keep no copy, and tell us — that is the finding.
- No denial-of-service, no load or stress testing against the live service, no phishing or social engineering of our staff or customers.
- You give us time to fix the problem before making it public. If we go quiet past the response times above, that understanding no longer binds you.
Step outside those lines and the safe harbour does not apply. Stay inside them and it does — including when the research turns up nothing.
What is in scope
In scope: the TEELS application, its REST API and MCP endpoints, this website, and anything else we operate that you can reach from them.
Out of scope, and better reported elsewhere:
- Issues in services we merely use — our hosting providers, the payment provider, the weather data source. Report those to whoever runs them.
- Missing security headers or TLS settings with no demonstrated impact.
- Raw output from an automated scanner, with no analysis of what it actually allows.
As of: August 2026