Coordinated Vulnerability Disclosure

Found a vulnerability?
Please tell us.

No system is perfect. Spotted something wrong in a service of ISPWeb B.V.? Report it to our CSIRT. We respond within three working days and keep you posted until it is resolved.

Machine readable at /.well-known/security.txt, and you can encrypt using our PGP key.

Ground rules

Please do

  • Report as soon as possible after your discovery.
  • Give us enough detail to reproduce the issue.
  • Keep it confidential until it has been resolved.

Please don't

  • Do not access or alter third-party data.
  • No DoS, spam or social engineering.
  • Do not dig deeper than needed to demonstrate the issue.

Stick to these rules and we will not take legal action. We do not run a bug bounty programme and do not pay rewards.

How it works
1

You report

Describe what you found and how we can reproduce it.

2

We confirm

Within three working days, naming a contact person.

3

We fix it

Investigation, impact assessment and a fix. We keep you posted.

4

We go public together

Disclosure in consultation. On request we credit you as the finder.