Letro Tech GmbH welcomes reports of security vulnerabilities in letro.com and the Letro applications. We take every report seriously and would rather hear about a problem from you than from anyone else.
How to report
Email [email protected]. Include enough detail for us to reproduce the issue: the affected URL, app version or component, steps to reproduce, and any proof-of-concept material. If you would like to encrypt your report, ask us for a key in your first message.
What you can expect from us
- We acknowledge reports within 3 business days.
- We aim to resolve confirmed vulnerabilities within 90 days and will keep you informed of progress.
- We will tell you when the issue is fixed, and — with your agreement — credit you.
What we ask of you
- Do not access, modify or delete data that is not your own.
- Do not degrade or disrupt the service, and do not use automated scanning that generates significant load.
- Do not use social engineering, phishing or physical attacks against Letro staff or customers.
- Give us reasonable time to fix the issue before any public disclosure.
Safe harbour
We will not pursue legal action against researchers who act in good faith, follow the rules above, and report promptly. If you are unsure whether a test is in scope, ask first.
Bug bounty
Letro does not currently operate a paid bug bounty programme.
Last updated: 4 September 2026

