Responsible Disclosure

At 10KB we take the security of our software and systems seriously. Even with careful attention to security, a weak spot can still exist. If you find a vulnerability in our system or software, please notify us right away so we can act. Your help lets us keep improving protection for our users and systems.

Responsible Disclosure

What we ask of you

You can also call us on 0246690518.

  • Email your findings as soon as possible to info@10kb.nl, with enough information to reproduce the problem so we can solve it.
  • Do not abuse the vulnerability further than necessary to demonstrate it.
  • Do not share the vulnerability with others until it has been resolved.
  • Do not use attacks on physical security, social engineering, distributed denial-of-service (DDoS), spam, or third-party applications.
  • Do not change or delete data and do not make changes to the systems.
  • Be restrained in approaching other people's personal data.

What we promise

  • We respond within five working days to your report with an initial assessment and an expected date for a solution.
  • We treat your report confidentially and do not share your personal data with third parties without your consent, unless this is legally required.
  • We keep you informed of the progress of resolving the vulnerability.
  • If you adhere to the conditions above, we will not take legal action as a result of the report.
  • We will, if you want, mention your name as the discoverer of the reported vulnerability.

What falls out of scope

Reports about the following matters we generally do not process, because they do not in themselves form a direct security risk:

  • The absence of best practices without demonstrable abuse (such as missing security headers or SPF/DKIM/DMARC settings).
  • Vulnerabilities that only work in strongly outdated browsers or operating systems.
  • Reports from automated scanners without substantiation of the impact.

Unsure whether your report falls within Glossary · In briefscopeScope defines the boundaries of a project or assignment: which goals, activities and results are included and which are excluded.Read more? Send it in anyway, then we will gladly look at it.

Finally

This responsible disclosure policy is not an invitation to actively and extensively scan our systems for vulnerabilities. We monitor our systems ourselves, so there is a good chance a scan will be picked up and investigated, resulting in unnecessary costs. Thank you for your contribution to a safer 10KB.

CONTACT

Get in touch with us

Have a question or want to discuss your software? Leave your details and we will get back to you soon.