Responsible disclosure/.well-known/security.txt

What the policy covers

The policy applies to systems managed by CodeSprinter. Applications we host for clients are covered as well; in that case we coordinate the handling with the client.

In scope

  • codesprinter.nl and codesprinter.net
  • mijn.codesprinter.nl (client portal)
  • Applications and infrastructure CodeSprinter manages for clients

Out of scope

  • Third-party systems that are not part of the environment managed by CodeSprinter
  • Findings that can only be demonstrated through (D)DoS, brute force or social engineering
  • Missing best practices without a demonstrable security risk, such as version disclosure or e-mail configuration without concrete impact

Rules for a responsible report

A report is responsible if you:

  1. investigate the vulnerability only as far as needed to demonstrate that it exists;

  2. do not view, copy, modify or delete data and do not disrupt the service;

  3. do not use social engineering, phishing, brute force or (D)DoS;

  4. do not install malware or backdoors;

  5. do not share the vulnerability with third parties until we have had the opportunity to fix it;

  6. report as soon as possible after discovery, in Dutch or English.

What you can expect from us

  1. Within 3 business days

    we confirm receipt of your report.

  2. Within 10 business days

    we let you know our initial assessment and how we will follow up.

  3. Remediation

    follows the deadlines in our vulnerability management policy: critical within 48 hours, high within 7 days, medium within 30 days, low within 90 days. We keep you informed of progress.

Recognition if you wish, we credit you as the reporter once the issue is fixed. Staying anonymous is fine too.

No bug bounty CodeSprinter does not offer financial rewards for reports, unless agreed in writing in advance.

How to report a vulnerability

[email protected]
  1. E-mail [email protected]

    Put "CVD" or "Responsible disclosure" in the subject line. This address is read directly by the owner.

  2. Describe what you found

    Which system or URL, the steps to reproduce it and, if you have one, a proof of concept. The more concrete, the faster we can act.

  3. Encrypt sensitive details if you wish

    If you want to encrypt the report with PGP, request the public key via the same address. The current details are in our security.txt.

Read more

The full policy, including how we assess and remediate vulnerabilities internally, is in our Vulnerability Management Policy. How security and privacy are built into our services is described in the Security & Privacy Statement.