Found a vulnerability? Tell us.
We take the security of Wendbaarsturen seriously, but no system is flawless. If you find a weak spot, we would like to hear it directly from you, so that we can close it before anyone abuses it. This page is our policy for coordinated vulnerability disclosure, following the guidance of the Dutch National Cyber Security Centre.
What this policy covers
This policy applies to everything we build and run ourselves:
- the website and the software on wendbaarsturen.nl, including the programming interface under /api/;
- the AI connection (MCP and OAuth) and the connections for signing in through the organisation (SSO and SCIM).
Not covered by this policy are the services of our suppliers (hosting, database, email); report a vulnerability there to that supplier. Also not part of this policy: overloading the service, social engineering of our people or customers, physical access, and findings that come only from automated scanners without demonstrable impact.
What we ask of you
- Go no further than is needed to demonstrate the vulnerability. Proof that you can reach something is enough; viewing, copying, changing or deleting data is not.
- Use only your own account or an environment you have been given for it. Leave the data of other users or organisations alone.
- Do not share the finding with others and do not make it public before we have solved it and we have agreed a moment for publication together.
- Do not use the vulnerability to gain an advantage for yourself or anyone else.
- Tell us enough to reproduce the problem: which part, which steps, what you saw.
What we promise
- We confirm receipt of your report within three working days and keep you informed of the progress.
- We treat your report confidentially and do not share your details with third parties without your consent, unless the law obliges us to.
- If you act in good faith and within the rules above, we will not report you to the authorities and will take no legal steps against you.
- We solve a high-risk vulnerability within 7 days of confirmation; other vulnerabilities as quickly as is reasonably possible, and we agree the term with you.
- No later than 90 days after your report we discuss publication. If you want to be named as the finder, we are happy to do so; if you would rather not, your name stays out of it.
- If the vulnerability affects customer data, we inform those customers ourselves, according to the agreements in our data processing agreement.
How to report
Send your report through our contact form with "vulnerability" as the subject. The machine-readable reporting point under RFC 9116 is at wendbaarsturen.nl/.well-known/security.txt; it also states the expiry date of this reporting route.
If it concerns personal data that has already been leaked, our privacy statement applies as well.
Thank you
To everyone who helps us make Wendbaarsturen safer in a careful way: thank you. This policy was last updated on 4 September 2026.