Coordinated Vulnerability Disclosure

Report a vulnerability.

Despite all our care, our systems may contain a weakness. If you find one, please let us know so we can fix it as quickly as possible.

How to report

  • Email your findings to [email protected]. This address is also listed in our security.txt.
  • Describe the issue as precisely as you can: where it is, how you found it and how we can reproduce it.
  • Leave your contact details so we can keep you informed.

What we ask of you

  • Do not exploit the vulnerability, and go no further than needed to demonstrate it.
  • Do not view, copy, modify or delete other people's data.
  • No denial of service, social engineering, spam or physical attacks.
  • Do not install a back door or malware, not even to demonstrate the issue.
  • Do not share the vulnerability with others until it has been fixed.

What you can expect from us

  • We respond to your report within time frame, e.g. 3 working days with an initial assessment.
  • If you comply with the conditions above, we will not report you to the police or take legal action.
  • We treat your report confidentially and do not share your details without your consent.
  • We keep you informed of progress and, if you wish, credit you when the issue is resolved.

This policy follows the Coordinated Vulnerability Disclosure guideline of the Dutch National Cyber Security Centre (NCSC).