Found a security vulnerability?
Report your finding confidentially to DESAN. Responsible collaboration allows an issue to be investigated and resolved without unnecessarily putting users or data at risk.
Conditions and commitments.
Limit your research to what is necessary to demonstrate the vulnerability.
DESAN asks you to
- Share your findings with DESAN.
- Not exploit the issue beyond what is necessary to demonstrate the vulnerability.
- Not download unnecessary data or view, modify or delete third-party data.
- Not share the vulnerability with others before it has been resolved.
- Immediately delete any confidential data obtained once the issue has been resolved.
- Not carry out physical attacks, social engineering, DDoS attacks, spam or attacks on third-party applications.
- Provide sufficient information to reproduce the issue.
DESAN promises to
- Respond within five days with an assessment and expected resolution time.
- Not take legal action when you follow these conditions.
- Treat your report and personal data confidentially unless disclosure is legally required.
- Accept a report made under a pseudonym.
- Keep you informed of progress.
- Credit you as the discoverer in communications about the issue if requested.
- Where possible, collaborate on responsible disclosure after the issue has been resolved.
Send the technical details to security@desan.nl.
A possible data breach or privacy incident can be reported separately via AVG@desan.nl.
Documenten voor beveiligde meldingen
Use the DESAN Security Team public key when you need to send sensitive details in encrypted form.
Read the standards of conduct DESAN applies to careful and professional work.
Richtlijnen voor een veilige melding
Test only DESAN systems.
Do not attack third-party systems or applications. A vulnerability in an external supplier may be reported to DESAN when it demonstrably affects a DESAN service.
Minimise access and copies.
Do not view or download more data than is strictly necessary to prove the vulnerability. Stop immediately if personal or other confidential data becomes visible and describe this in the report.
Coordinate disclosure in advance.
Do not disclose the vulnerability publicly before it has been resolved. DESAN is open to coordinating any publication after the risk has been removed.
Reporting a data incident
A data incident is an event in which personal data may have been lost or accessed without authorisation. A personal data breach is a security breach resulting in the destruction, loss, alteration, unauthorised disclosure of or access to personal data.
Report a possible incident immediately to AVG@desan.nl and clearly state in the subject that it concerns a data incident or personal data breach. Share what is known, but do not collect or send additional personal data. DESAN will then assess whether notification to the Dutch Data Protection Authority is required within the statutory 72-hour period.
