{"id":38438,"date":"2026-03-23T10:03:39","date_gmt":"2026-03-23T09:03:39","guid":{"rendered":"https:\/\/hotelbird.com\/?page_id=38438"},"modified":"2026-03-23T10:03:40","modified_gmt":"2026-03-23T09:03:40","slug":"security-policy","status":"publish","type":"page","link":"https:\/\/hotelbird.com\/en\/security-policy\/","title":{"rendered":"Vulnerability Disclosure Policy (VDP)"},"content":{"rendered":"\n<p><strong>Version:<\/strong> 1.0<br><strong>Last Updated:<\/strong> March 17, 2026<br><strong>Language:<\/strong> English<\/p>\n\n\n\n<p><strong>1. Introduction and Commitment<\/strong><br>At Hotelbird, the security of our digital hospitality infrastructure and the protection of our partners&#8217; and guests&#8217; data are our highest priorities. In alignment with the recommendations of the <strong>German Federal Office for Information Security (BSI)<\/strong>, we maintain this policy to provide a clear framework for the responsible reporting of security vulnerabilities.<br>We recognize the vital role that independent security researchers play in the internet ecosystem and welcome efforts to improve our security posture.<\/p>\n\n\n\n<p><strong>2. &#8220;Safe Harbor&#8221; and Legal Guarantee<\/strong><br>Hotelbird will not initiate legal action (under German laws such as <strong>\u00a7 202a StGB<\/strong> &#8220;Data Espionage&#8221; or <strong>\u00a7 202b StGB<\/strong> &#8220;Interception of Data&#8221;) against researchers who:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Engage in vulnerability research without harming Hotelbird, its customers, employees, or third parties.<\/li>\n\n\n\n<li>Adhere strictly to the guidelines set forth in this policy.<\/li>\n\n\n\n<li>Do not access, modify, or delete data belonging to Hotelbird or its users.<\/li>\n\n\n\n<li>Provide us with a reasonable amount of time to remediate the issue before any public disclosure.<\/li>\n<\/ul>\n\n\n\n<p><strong>3. Guidelines for Responsible Research<\/strong><br>To qualify for Safe Harbor, we expect researchers to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Avoid Privacy Violations:<\/strong> If you accidentally encounter Personal Identifiable Information (PII) during your research, you must stop immediately, delete any local copies, and notify us.<\/li>\n\n\n\n<li><strong>No Disruption:<\/strong> Do not perform Denial of Service (DoS\/DDoS) attacks, brute-force testing, or any testing that might degrade the performance of our services.<\/li>\n\n\n\n<li><strong>No Social Engineering:<\/strong> Testing our employees, offices, or partners via phishing or physical access is strictly prohibited.<\/li>\n\n\n\n<li><strong>Confidentiality:<\/strong> Do not disclose vulnerability details to any third party or the public until Hotelbird has confirmed a fix and granted explicit permission.<\/li>\n<\/ul>\n\n\n\n<p><strong>4. Reporting Process and Requirements<\/strong><br>Please report vulnerabilities via the contact method specified in our <code>security.txt<\/code> file:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Primary Contact:<\/strong> <code><a href=\"mailto:itsecurity@hotelbird.com\" target=\"_blank\" rel=\"noreferrer noopener\">itsecurity@hotelbird.com<\/a><\/code><\/li>\n\n\n\n<li><strong>Encryption:<\/strong> We strongly recommend encrypting your report using our Public PGP Key (see <code><a href=\"https:\/\/hotelbird.com\/pgp-key.txt\" target=\"_blank\" rel=\"noreferrer noopener\">https:\/\/hotelbird.com\/pgp-key.txt<\/a><\/code>).<\/li>\n<\/ul>\n\n\n\n<p><strong>A valid report should include:<\/strong><\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Summary:<\/strong> A brief description of the vulnerability and its potential impact.<\/li>\n\n\n\n<li><strong>Steps to Reproduce:<\/strong> Clear, technical steps (or a PoC script) to reproduce the issue.<\/li>\n\n\n\n<li><strong>Environment:<\/strong> Browser version, OS, and the specific URL\/Endpoint affected.<\/li>\n\n\n\n<li><strong>IP Address:<\/strong> The IP address you used during your research (to help us distinguish your traffic from malicious attacks).<\/li>\n<\/ol>\n\n\n\n<p><strong>5. Handling of Personal Data (GDPR \/ DSGVO)<\/strong><br>In accordance with the <strong>EU General Data Protection Regulation (GDPR)<\/strong>:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Hotelbird acts as the Data Controller.<\/li>\n\n\n\n<li>Your report and contact details will be processed solely for the purpose of investigating and fixing the reported security issue (Art. 6 (1) (f) GDPR).<\/li>\n\n\n\n<li>If you find a data leak, do not download more data than the absolute minimum necessary to prove the vulnerability.<\/li>\n<\/ul>\n\n\n\n<p><strong>6. Our Commitment to You<\/strong><br>When you report a vulnerability to Hotelbird, we commit to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Acknowledgment:<\/strong> We will confirm receipt of your report within <strong>5 business days<\/strong>.<\/li>\n\n\n\n<li><strong>Investigation:<\/strong> We will perform a preliminary assessment and provide a status update within <strong>10 business days<\/strong>.<\/li>\n\n\n\n<li><strong>Transparency:<\/strong> We will keep you informed of our progress as we work on a remediation.<\/li>\n\n\n\n<li><strong>Recognition:<\/strong> With your permission, we may acknowledge your contribution to our security in our &#8220;Hall of Fame&#8221; (if applicable). <em>Note: At this time, Hotelbird does not offer a monetary Bug Bounty program.<\/em><\/li>\n<\/ul>\n\n\n\n<p><strong>7. Out-of-Scope Vulnerabilities<\/strong><br>While we review all reports, the following are generally considered out-of-scope:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Clickjacking on pages without sensitive actions.<\/li>\n\n\n\n<li>Missing security headers that do not directly lead to a vulnerability.<\/li>\n\n\n\n<li>SPF\/DKIM\/DMARC records.<\/li>\n\n\n\n<li>Known public files or directories (e.g., robots.txt).<\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Version: 1.0Last Updated: March 17, 2026Language: English 1. Introduction and CommitmentAt Hotelbird, the security of our digital hospitality infrastructure and the protection of our partners&#8217; and guests&#8217; data are our highest priorities. In alignment with the recommendations of the German Federal Office for Information Security (BSI), we maintain this policy to provide a clear framework [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-38438","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/pages\/38438","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/comments?post=38438"}],"version-history":[{"count":2,"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/pages\/38438\/revisions"}],"predecessor-version":[{"id":38440,"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/pages\/38438\/revisions\/38440"}],"wp:attachment":[{"href":"https:\/\/hotelbird.com\/en\/wp-json\/wp\/v2\/media?parent=38438"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}