diff --git a/SECURITY.md b/SECURITY.md
new file mode 100644
index 0000000000000000000000000000000000000000..9dc768a6f5f6c14365774064e2d4b49c696cca80
--- /dev/null
+++ b/SECURITY.md
@@ -0,0 +1,15 @@
+<!--
+SPDX-FileCopyrightText: 2022 FIT-Connect contributors
+
+SPDX-License-Identifier: EUPL-1.2
+-->
+
+# Security Vulnerabilities
+
+Our team is trying to make sure that our code is secure. Nevertheless, we are very grateful for anyone who finds a security vulnerability and reports it to us.
+
+Please do not report security vulnerabilities through GitLab directly. Because GitLab issues are public, this could result in directly disclosing the vulnerability.
+
+Please send any request regarding a potential security vulnerability with all the information that could help to `it-sicherheit <at> fitko.de`. See our [security.txt](https://www.fitko.de/.well-known/security.txt) for details.
+
+If possible please note the release version or the commit id of the main branch that you have investigated.