Responsible Disclosure Policy

At Pro4all the security of our systems is extremely important. Despite our care for security during product development and maintenance, a weak point can still exist.

We ask you to tell us if you find a weak point in one of our systems, as soon as possible, so that we can act immediately to protect our customers and their data.

We recognise everyone who takes the time and effort to report a vulnerability in line with this policy. We do not offer monetary rewards.

How to report?

Submit this form, or email us at info@pro4all.nl.

What your report should include

The more of this you can give us, the faster we can validate and resolve the issue.

  1. Title
  2. Type of vulnerability
  3. Severity: low, medium, high or critical
  4. Affected asset (required): website, IP address, product or service
  5. Description of the vulnerability (required)
    • A short summary
    • Supporting files such as a screenshot or a video
    • Any notes towards a solution
  6. Steps to reproduce (required)
    • A clear description of the steps needed to reproduce the issue
    • Proof of concept code, if you have it
  7. Impact: what an attacker could achieve by exploiting it
  8. Test data, timestamps and the URLs of the systems involved
  9. Contact details, if you want a response

Reports from automated tools with no explanatory documentation are not covered by this policy.

How to proceed

This policy is not an open invitation to actively scan our network and applications for vulnerabilities. Our monitoring will most likely detect a scan, and we will investigate it.

We ask you to:

  • Not exploit the vulnerability further than you need to in order to demonstrate it. Do not download, change, delete or upload data, and do not upload code.
  • Not run automated scans to find vulnerabilities.
  • Not attack physical security, and not use social engineering, distributed denial of service or spam.
  • Not target the applications of third parties.
  • Not share information about the issue with anyone else until it is resolved.
  • Delete any confidential data you obtained as soon as you no longer need it for the report, and in any case once the vulnerability has been resolved.
  • Give us enough information to reproduce and analyse the problem, and a way to ask you questions.

Our promise

When you report a security issue, we will act as follows:

  • You receive confirmation of receipt within 10 working days of your report.
  • You receive our assessment of the issue and an expected resolution date within 10 working days of that confirmation.
  • We keep you informed of progress, and we tell you when the issue is closed. We may ask you to confirm that the fix is adequate.
  • We handle your report confidentially. We do not share your details with third parties without your permission, unless we have to in order to meet a legal obligation.
  • We take no legal steps against you in relation to your report, provided you have kept to the conditions above.
  • Once an issue is resolved, we are happy to discuss publishing your findings. We ask you to coordinate the timing with us so that affected users are protected first.

Which vulnerabilities qualify

Any design or implementation issue that is reproducible and affects security can be reported. Common examples are remote code execution, unauthorised access to accounts or data, improper error handling, an actively exploitable backdoor, information leakage and misconfiguration.

The following are outside the scope of this policy:

  • Issues that cannot be exploited, including a failure to follow best practice, and missing security headers that do not lead directly to an exploitable vulnerability.
  • The use of a library that is publicly known to be vulnerable, without evidence that it is exploitable here.
  • Vulnerabilities that require direct physical access to a device or network.
  • Weak cipher suites.
  • Distributed denial of service, spam and mass registration.
  • Social engineering in any form.
  • Error messages or error pages that contain no sensitive data.
  • Vulnerability scan reports for software we use publicly.
  • Issues caused by an outdated operating system, browser or plugin.
  • Issues we have already been notified about.

What this policy is not for

This scheme is not intended for:

  • Complaints
  • Reports that the website is unavailable
  • Phishing reports
  • Fraud reports

For those, please contact our support team at support@pro4all.nl.

Submit your report

Use the form above. If you would rather email us, or you want to report anonymously, write to info@pro4all.nl.

Acknowledgements

  • Sudais Nazir