On this page
1. Security principles
Our security program is guided by:
- Data minimization: Collect and retain only information with a documented purpose.
- Least privilege: Limit staff and system access to what is needed.
- Secure defaults: Keep profiles private or access-controlled unless a member chooses otherwise.
- Layered protection: Avoid relying on one control to prevent or contain failure.
- Prompt response: Investigate credible reports and incidents without unnecessary delay.
- Honest claims: Publish only safeguards that are implemented and supportable.
- Continuous improvement: Review controls as the service, threats, and team change.
2. Account security
Deutsche Kraniche Virtual accounts use:
- Email verification;
- Passwords stored using a modern, one-way, salted password-hashing method;
- Multi-factor authentication;
- Protected password-reset and account-recovery flows;
- Session and authentication controls;
- Logging and review of relevant authentication events; and
- Rate limiting or equivalent abuse controls where appropriate.
Members are responsible for using a unique password, protecting recovery methods and MFA factors, and promptly reporting suspected compromise. Deutsche Kraniche Virtual will not ask for a password or current MFA code through ordinary email, Discord, or community chat.
3. Access to member information
Access to non-public member information is restricted by role and operational need. Sensitive actions and access should be attributable to individual staff accounts. Staff with access to personal information or conduct reports receive confidentiality and security guidance.
Deutsche Kraniche Virtual periodically reviews privileged access and removes it when a role changes or access is no longer required.
4. Application and infrastructure safeguards
Depending on the service component, safeguards may include encryption in transit, secure configuration, dependency maintenance, protected secrets, access logging, backups, recovery testing, monitoring, rate limiting, and separation of production access.
We intentionally do not publish server addresses, network diagrams, provider-specific configurations, detailed monitoring coverage, internal defensive tooling, or information that would materially assist an attacker. Provider categories and personal-data disclosures appear in the Privacy Notice.
5. Software and updates
Official Deutsche Kraniche Virtual software and downloads are distributed through the Deutsche Kraniche Virtual website or authenticated member portal. Members should install updates through official channels, verify unexpected requests, and avoid redistributed packages.
Deutsche Kraniche Virtual prioritizes security updates based on risk. We may require an update or disable an outdated client version when necessary to protect members, data, or service integrity.
6. Backups and recovery
Deutsche Kraniche Virtual maintains backups appropriate to the service’s recovery needs. Backup access is restricted, and backups are overwritten through a documented rotation cycle. Backups are not intended as permanent archives of deleted member information.
7. Incident response
When Deutsche Kraniche Virtual identifies a suspected security incident, we aim to:
- Triage and contain the issue.
- Preserve necessary evidence with restricted access.
- Determine affected systems and information.
- Remove or mitigate the cause.
- Restore safe service operation.
- Notify affected people, providers, or authorities when required.
- Document lessons and track corrective actions.
Live availability and incident updates appear on our separate status site. Durable policy changes or a completed public incident summary may appear on the trust site when useful and safe.
8. Reporting a vulnerability
Send suspected security vulnerabilities to [email protected]. Include:
- The affected service or URL;
- A clear description of the issue and potential impact;
- Reproduction steps or a proof of concept using the minimum data necessary;
- Relevant timestamps; and
- A safe way to contact you.
Do not include passwords, authentication tokens, unrelated personal information, destructive payloads, or another person’s data unless strictly necessary to explain the issue.
9. Good-faith research guidelines
We welcome good-faith research that:
- Avoids privacy violations, service disruption, data destruction, social engineering, and physical intrusion;
- Uses only accounts and data you own or have explicit permission to test;
- Stops when personal information, credentials, or a path to material harm is encountered;
- Does not access more information than needed to demonstrate the issue;
- Gives Deutsche Kraniche Virtual a reasonable opportunity to investigate before public disclosure; and
- Complies with applicable law.
Activities such as denial of service, spam, malware delivery, credential attacks, extortion, staff or volunteer impersonation, and testing third-party systems are not authorized.
Deutsche Kraniche Virtual will not initiate legal action against research that it determines, in good faith, followed these guidelines. This statement cannot authorize activity against third parties or bind law-enforcement authorities.
10. Response expectations
We aim to acknowledge a credible security report within three business days and provide status updates as appropriate. Resolution time depends on severity, complexity, provider involvement, and safe deployment requirements. We do not promise rewards, but we may recognize helpful reports with the reporter’s permission.
11. Security-related account concerns
For suspected compromise of your own account, use the recovery controls on the sign-in page or contact [email protected].
For privacy requests, use [email protected].
For community misconduct that is not a vulnerability, contact [email protected].
12. Changes
We update this statement as verified controls and risks change. Previous versions remain available in Policy History.
