Responsible disclosure
Have you found a vulnerability?
We are constantly working to ensure the security and optimisation of our technical infrastructure and products. Even though we do our very best, it is possible that an error or vulnerability may still be present in one of our products and/or services. Please report all information and details regarding the vulnerability you have found, the steps you took to reproduce it, and where the vulnerability occurs.
Report issue to security@vanwyk.nl
Our specialists will get to work on your report straight away and will respond as soon as possible. Whilst the investigation is ongoing, we ask that you treat your findings with discretion. We will, of course, keep you informed of any follow-up.
Examples of vulnerabilities
- SQL injection Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- Weak encryption
- Information leakage
- Authentication/authorisation issues
What we ask of you?
We ask you to obey to the following rules:
- Do not attack physical security or people (social engineering).
- Do not use any form of Distributed Denial of Service attacks.
- Submitting a notification under a pseudonym is allowed. If you feel the data is so sensitive that you wish to encrypt it, we ask you to notify us beforehand. We will then provide you with an email address to which you can send your PGP encrypted email.
- Delete all confidential information obtained through the breach as soon as possible after reporting it, but always after consulting us to ensure we can reproduce the issue.
- Do not misuse the problem by downloading more data than necessary to demonstrate the breach. Do not inspect, remove or alter third-party data.
- Do not publish or share the issue with others until it has been resolved and discussed and agreed by us.
What we promise you!
- We feel it is essential that vulnerabilities are reported to us as soon as possible so that we can take immediate action to secure our environment. All notifications will, therefore, always be gratefully received. We will not consider any legal steps against those who notified us and gained unauthorised access to sensitive information if they have complied with the above points.
- We will treat your notification with confidentiality and will not share your personal details with third parties without your consent unless necessary to comply with a statutory obligation.
- We can publish the relevant content of the resolved issue on our website unless there are reasons not to do so. That might be the case if the fixed issue has led to discovering a related vulnerability that has not yet been resolved or when publication could damage our reputation.
