Responsible Disclosure
At Creosoft we take the security of our own systems and of the systems we build for our clients seriously. Despite our care, a vulnerability may still exist. If you find one, we would like to hear about it so we can fix it quickly.
This policy explains how to report a vulnerability to us and what you can expect in return. It follows the responsible disclosure guidance published by the Dutch National Cyber Security Centre (NCSC).
1. How to report
Send your report by email to info@creosoft.nl with “Responsible Disclosure” in the subject line.
To help us assess and resolve the issue quickly, please include:
- a description of the vulnerability and its potential impact;
- the exact steps needed to reproduce it, including URLs and any parameters used;
- the date and time of your testing;
- screenshots or a short recording where that makes the issue clearer;
- how we can reach you for follow-up questions.
Reports in English or Dutch are both welcome.
2. What we ask of you
To keep disclosure responsible on both sides, we ask that you:
- report the issue to us as soon as you discover it, and give us reasonable time to resolve it before making anything public;
- do not exploit the vulnerability further than is necessary to demonstrate it;
- do not access, modify, or delete data that does not belong to you. If you accidentally access personal data, stop immediately and tell us in your report;
- do not use attacks on physical security, social engineering, distributed denial of service, spam, or third-party applications;
- do not install malware, backdoors, or any persistent access;
- do not share the vulnerability with others until it has been resolved;
- keep your own report and any evidence confidential, and delete any data obtained once the issue is closed.
3. What you can expect from us
- We acknowledge your report within 3 business days.
- We send an initial assessment, including our view on severity and an expected resolution timeline, within 10 business days.
- We keep you informed of progress while we work on a fix.
- We resolve confirmed vulnerabilities as quickly as is reasonably possible, prioritised by severity.
- We treat your report confidentially and do not share your personal details with third parties without your permission, unless we are legally required to do so.
- With your consent, we are happy to credit you publicly once the issue is resolved. You may also choose to remain anonymous.
4. Legal position
If you follow the conditions in section 2, we will not report your findings to the authorities and will not pursue legal action against you in connection with the report. This is our commitment; it does not remove any obligations you may have under Dutch law, and we cannot waive claims on behalf of our clients or other third parties.
If you are testing a system that Creosoft built but that is operated by one of our clients, please still report it to us. We will coordinate with the system owner on your behalf.
5. Scope
This policy applies to systems owned and operated by Creosoft, including this website and the infrastructure directly supporting it.
The following are explicitly out of scope:
- findings from automated scanners without a demonstrated, practical impact;
- missing best-practice headers or configuration hardening with no exploitable consequence;
- reports about outdated browsers or software running on your own device;
- vulnerabilities in third-party services we merely use, which should be reported to that provider;
- social engineering of our staff or clients, and physical attacks on offices or equipment.
6. Rewards
We do not operate a paid bug bounty programme. For a genuinely new and significant vulnerability, reported in line with this policy, we offer our sincere thanks, public credit if you want it, and a token of appreciation at our discretion.
7. Contact
- Creosoft
- Security reports: info@creosoft.nl
- KVK-nummer: 97079413
- Country: Netherlands
For non-security questions, please use our support page instead.