Principles
Responsible disclosure policy
We consider the security of our systems a top priority. However, regardless of how much effort we put into securing our systems, vulnerabilities may still exist.
If you discover a vulnerability, we would like to be informed so that we can take steps to address it as quickly as possible. We ask you to help us better protect our customers and our systems.
Please do the following:
- Email your findings to isms@solvy.nl. Encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands;
- Do not exploit the vulnerability or issue you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability, or by deleting or modifying data belonging to others;
- Do not disclose the issue to others until it has been resolved;
- Do not use attacks against physical security, social engineering, distributed denial-of-service attacks, spam, or third-party applications; and
- Provide us with sufficient information to reproduce the issue so that we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability will be sufficient, but complex vulnerabilities may require further explanation.
We aim to resolve all issues as quickly as possible, and we would like to play an active role in the eventual publication about the issue once it has been resolved.
PGP Encryption
You can get our PGP public key here.
Fingerprint: 778B AD6A E02A 6F62 D8E1 7927 BDEF 1109 32AF B5CD
Please verify the fingerprint before using the key to ensure that you are using the correct public key.