Report a vulnerability
Security is at the heart of our services. We take great care in securing our websites and systems. Still, no system is perfect. Have you found a weakness? We would like to hear about it, so we can fix it quickly.
How do you report a vulnerability?
Send an e-mail to security@softcrow.com including:
- a description of the vulnerability
- the steps to reproduce the issue (or a proof of concept, screenshot or URL)
- how we can reach you in case of questions
You can report in Dutch or English.
What we promise
- You will receive a confirmation of your report within 3 working days.
- We will keep you informed of the assessment and the resolution.
- We treat your report confidentially and will not share your details with third parties without your consent.
- We trust you to follow the ground rules below.
Ground rules
- Do not go further than necessary to demonstrate the vulnerability.
- Do not view, copy, modify or delete data that is not yours.
- Do not use attacks that affect the availability or integrity of our services.
- Focus your research on our systems, not on people or locations: do not use social engineering and do not attempt to gain physical access.
- Do not share the vulnerability with others or make it public before the issue has been resolved and we have coordinated this together.
- Delete any data obtained during your research as soon as you have made your report.
No reward
We do not offer a (financial) reward for reports. What we do offer: our sincere thanks. You help us improve our security.