Draft · 6 October 2026

Responsible disclosure

If you find a weakness in secctl.io, please tell us, so we can fix it before anyone misuses it.

How to report

Email your report to security@secctl.io. Please include:

  • where the vulnerability is, for example the web address;
  • what you did, so we can reproduce it;
  • what you saw, and what you think someone could do with it;
  • how we can reach you.

You can write in English or Dutch. Our reporting address is also in security.txt.

What this policy covers

The secctl.io website and the module environments secctl.io runs for customers. Services run by other parties are not covered. If you find something there, please report it to that party.

What we ask of you

  • Do no more than you need to demonstrate the vulnerability.
  • Don’t view, copy or change other people’s data. If you come across any, stop and delete what you have.
  • No denial-of-service attacks, no social engineering and no physical access.
  • Don’t install a backdoor, and don’t share the vulnerability with anyone else until it is fixed.

What we do

  • We confirm your report within 5 working days.
  • We tell you our assessment and when we expect to fix it, and keep you informed.
  • If you follow this policy, we won’t report you to the police.
  • We treat your report confidentially and don’t share your details without your permission.
  • Once it is fixed, we agree together whether and how to publish. If you like, we credit you by name.

We don’t run a bug bounty programme.

What this policy is based on

This policy follows the Coordinated Vulnerability Disclosure principles of the Dutch National Cyber Security Centre.

Try it with your own team for 30 days

You won't need payment details. Rather talk first? Pick a time that suits you.

Try it free for 30 daysNo payment details. It stops by itself if you don’t choose to continue.
Book a call30 minutes, at a time that suits you.