Report a vulnerability
Found a weak spot in our systems, hardware or applications? Here is how to report it, and what you can expect from us.
What we ask
Report a vulnerability to us before sharing it with anyone else, so we can fix it before someone abuses it. We value a report like this, even if you do not work for us and even if we never asked for it. If you stick to this policy, we will not take legal action against you.
How to report
Send your report to [email protected].
Please include:
- What you found and where: a URL, an IP address, a device model or a screen name.
- How we can reproduce it, step by step and as precisely as possible.
- What you think the impact is: what goes wrong if someone acts in bad faith.
- How we can reach you, if you would like a reply.
Want to report encrypted? Use the PGP key named in security.txt.
What you can expect from us
An acknowledgement of receipt, from a person, not an automated message.
Our first assessment: whether we recognize it, how serious we consider it, and what we plan to do about it.
Updates on progress, even if it takes longer than expected.
We aim to fix a confirmed vulnerability within ninety days. If we cannot, we explain why and when we expect to. For anything being actively exploited, we work on it without delay.
Disclosure
We would rather publish together than apart.
- We ask you not to disclose the vulnerability publicly until it is fixed.
- Once it is fixed, you are welcome to publish about it; we are happy to discuss the timing and the content.
- If you want to be credited as the reporter, we will do so. If you would rather stay anonymous, we will not name you.
- We ask you not to retain, share or publish data belonging to anyone else.
What is fine while researching
- Researching our publicly reachable systems.
- Demonstrating a vulnerability with the minimum needed to prove it.
- Testing with your own account and your own hardware.
What is not allowed
This is not an open invitation to try anything. Outside this policy:
- Using or altering data belonging to others, or retrieving more data than needed to demonstrate the issue.
- Attacks that make the service unreachable, even as a test.
- Social engineering, phishing and attempts to gain physical access.
- Leaving behind software such as a backdoor or a script that keeps running.
- Automated scanning of our systems at a scale that hinders the service.
- Sharing the vulnerability with others before it is fixed.
Anyone who does not stick to this falls outside the protection of this policy.
What falls outside this policy
Some reports get an acknowledgement but are not treated as a vulnerability:
- Reports consisting solely of scanner output, with no demonstrated impact.
- Missing security headers or settings with no demonstrable impact.
- Vulnerabilities in third-party software the vendor has already fixed and we are still rolling out -- reporting is welcome, but handling runs through that vendor.
- Vulnerabilities that only work with physical access to the device, unless that also compromises the security of other devices.
- Weaknesses in the gate installation itself; that is not ours, and we will point you to the manufacturer.
Reward
We have no bug bounty program. We thank you, credit you if you want that, and are happy to send you something as a token of appreciation. Anyone looking for payment should know we do not offer it.
Contact
- Reports: [email protected]
- Other questions: [email protected]
- Postal address: Colloport B.V., Laan van Selis 3, 5283 PG Boxtel, the Netherlands