Responsible disclosure
We consider the security and data of our systems a top priority. Since we are committed to system security, we understand and appreciate the added value of security researchers who help us improve.
Find a vulnerability? Disclose it responsibly, we’ll listen, rate it, fix it, and reward you.
Program rules
In order to protect our systems and users, we’ve compiled a short list of rules regarding vulnerability disclosure. Following them keeps your report processable and rewardable.
Stay inside the boundary
Only systems within our scope are applicable. Report the vulnerability as quickly as possible after discovery. You’re welcome to use your own data (name, email address) to demonstrate the issue, but a pseudonym works just as well.
Don’t exploit it
Don’t take advantage of the issue, no downloading more data than necessary, no deleting or modifying anyone’s data, no installing malware, no system changes. Demonstrate, don’t exploit.
Confidential until fixed
Don’t reveal the problem until it’s resolved. Provide enough information to reproduce it, a Proof-of-Concept is ideal. For duplicate reports, only the first one received is awarded, provided it can be reproduced.
We ask that all disclosures are kept confidential to protect our community. For major disclosures, a joint public statement may be possible, but this must be agreed beforehand via responsibledisclosure@on2it.net.
Rated, ranked, and paid out
All responsible disclosures are rated by our security professionals, who determine at their discretion whether a reward is due and its size. Rewards are paid out using the Tremendous platform. Five criteria drive the rating.
Reproducibility
Reproducibility and verifiability of the vulnerability. Without it, we can’t confirm or fix it.
Severity
Severity of the vulnerability disclosed. Higher impact = higher rating.
Exploitability
Likelihood that the vulnerability would have been exploited in the wild before disclosure.
Asset criticality
Criticality of the assets affected by the vulnerability, what was at stake.
Communication
Quality of the communication, clear, complete, and constructive reports get higher ratings.
What’s in, what’s out
Disclosures are only eligible if they are in line with our defined scope.
In scope: https://*.on2it.net/ and https://*.on2it.nl/
Out of scope, no need to report:
- The subdomains
academy.on2it.net,zerotrust.on2it.netandfeedback.on2it.net - SPF/DKIM/DMARC suggestions
- Contact forms without submission limits
- Known public files (e.g.
robots.txt) - Banner disclosure without PoC
- Missing/lax security headers or Secure/HTTPOnly flags on non-sensitive cookies
- Informational disclosures about software versions
Minimum data, maximum care
When you report a vulnerability we only collect your name (or pseudonym) and email address in order to communicate with you.
Disclose it responsibly
Send us your report and a way to reproduce it. We’ll take it from there, rate it, fix it, and pay you out for the work.