In scope
- codesprinter.nl and codesprinter.net
- mijn.codesprinter.nl (client portal)
- Applications and infrastructure CodeSprinter manages for clients
CodeSprinter values the work of security researchers and ethical hackers. If you find a vulnerability in one of our websites, the client portal or an application we manage, we would like to hear about it first, so we can fix it before anyone can abuse it.
The policy applies to systems managed by CodeSprinter. Applications we host for clients are covered as well; in that case we coordinate the handling with the client.
A report is responsible if you:
investigate the vulnerability only as far as needed to demonstrate that it exists;
do not view, copy, modify or delete data and do not disrupt the service;
do not use social engineering, phishing, brute force or (D)DoS;
do not install malware or backdoors;
do not share the vulnerability with third parties until we have had the opportunity to fix it;
report as soon as possible after discovery, in Dutch or English.
we confirm receipt of your report.
we let you know our initial assessment and how we will follow up.
follows the deadlines in our vulnerability management policy: critical within 48 hours, high within 7 days, medium within 30 days, low within 90 days. We keep you informed of progress.
Recognition if you wish, we credit you as the reporter once the issue is fixed. Staying anonymous is fine too.
No bug bounty CodeSprinter does not offer financial rewards for reports, unless agreed in writing in advance.
Put "CVD" or "Responsible disclosure" in the subject line. This address is read directly by the owner.
Which system or URL, the steps to reproduce it and, if you have one, a proof of concept. The more concrete, the faster we can act.
If you want to encrypt the report with PGP, request the public key via the same address. The current details are in our security.txt.
The full policy, including how we assess and remediate vulnerabilities internally, is in our Vulnerability Management Policy. How security and privacy are built into our services is described in the Security & Privacy Statement.