How to report
Email your report to security@secctl.io. Please include:
- where the vulnerability is, for example the web address;
- what you did, so we can reproduce it;
- what you saw, and what you think someone could do with it;
- how we can reach you.
You can write in English or Dutch. Our reporting address is also in security.txt.
What this policy covers
The secctl.io website and the module environments secctl.io runs for customers. Services run by other parties are not covered. If you find something there, please report it to that party.
What we ask of you
- Do no more than you need to demonstrate the vulnerability.
- Don’t view, copy or change other people’s data. If you come across any, stop and delete what you have.
- No denial-of-service attacks, no social engineering and no physical access.
- Don’t install a backdoor, and don’t share the vulnerability with anyone else until it is fixed.
What we do
- We confirm your report within 5 working days.
- We tell you our assessment and when we expect to fix it, and keep you informed.
- If you follow this policy, we won’t report you to the police.
- We treat your report confidentially and don’t share your details without your permission.
- Once it is fixed, we agree together whether and how to publish. If you like, we credit you by name.
We don’t run a bug bounty programme.
What this policy is based on
This policy follows the Coordinated Vulnerability Disclosure principles of the Dutch National Cyber Security Centre.