Security Delta (HSD) Foundation’s Responsible Disclosure Policy, in addition to the the Guideline Responsible Disclosure published by the NCSC.
We of course take the security of our website and systems very seriously. Despite our efforts to secure our website and systems, there could still be weak spots.
If you have found a weakness in one of our websites/systems, we would like to hear about it so we can take action as soon as possible. We would like to cooperate with you in order to better protect our partners and systems.
We would like to ask you to:
- Email your findings to This email address is being protected from spambots. You need JavaScript enabled to view it. and This email address is being protected from spambots. You need JavaScript enabled to view it..
- Not misuse your findings by, for example downloading more data than necessary or looking into, deleting and modifying data from third parties.
- Not share information about the issue with others until it is solved and erase all confidential data obtained through the leak directly afterwards.
- Not use attacks on physical security, social engineering, distributed denial of service, spam or third-party applications.
- Provide sufficient information to reproduce the problem so we can fix it as soon as possible. In most cases, providing the IP-address or URL of the affected system together with a description of the problem would be sufficient, but more detailed information might be necessary for more complex problems.
What we promise:
- We will respond to your report with an assessment of the problem and expected date for a solution within 5 workdays.
- If you have complied with the above conditions, we will not take legal actions against you.
- We will treat your report confidentially and your personal details will not be shared with third parties without your permission unless this is necessary to meet our legal obligations. Reporting using a pseudonym is possible as well.
- We will keep you informed about the progress of solving the problem.
- If you wish, we will include your name as discoverer in our communications about the problem.
- As a non-profit organisation, we cannot pay a financial reward for a notification. However, as a reward, we could offer you a podium and attention and/or we could get you into contact with members of our network of security organisations.
We strive to resolve any problems as quickly as possible and we like to be involved in a possible publication on the issue after it is resolved.
We would like to thank Floor Terra for making the example available, on which this disclosure is based.