ON2IT - Zero Trust Innovators

Select your region

Talk to us →
Security

Responsible disclosure

We consider the security and data of our systems a top priority. Since we are committed to system security, we understand and appreciate the added value of security researchers who help us improve.

Find a vulnerability? Disclose it responsibly, we’ll listen, rate it, fix it, and reward you.

Report a vulnerability Trust Center
The rules

Program rules

In order to protect our systems and users, we’ve compiled a short list of rules regarding vulnerability disclosure. Following them keeps your report processable and rewardable.

In scope
Stay inside the boundary

Only systems within our scope are applicable. Report the vulnerability as quickly as possible after discovery. Use your own data (name, email address) to demonstrate the issue; pseudonyms are fine.

Be careful
Don’t exploit it

Don’t take advantage of the issue, no downloading more data than necessary, no deleting or modifying anyone’s data, no installing malware, no system changes. Demonstrate, don’t exploit.

Keep quiet
Confidential until fixed

Don’t reveal the problem until it’s resolved. Provide enough information to reproduce it, a Proof-of-Concept is ideal. For duplicate reports, only the first one received is awarded, provided it can be reproduced.

We ask that all disclosures are kept confidential to protect our community. For major disclosures, a joint public statement may be possible, but this must be agreed beforehand via responsibledisclosure@on2it.net.

Rewards

Rated, ranked, and paid out

All responsible disclosures are rated by our security professionals to calculate a possible reward. Rewards are paid out using the Tremendous platform. Five criteria drive the rating.

01

Reproducibility

Reproducibility and verifiability of the vulnerability. Without it, we can’t confirm or fix it.

02

Severity

Severity of the vulnerability disclosed. Higher impact = higher rating.

03

Exploitability

Likelihood that the vulnerability would have been exploited in the wild before disclosure.

04

Asset criticality

Criticality of the assets affected by the vulnerability, what was at stake.

05

Communication

Quality of the communication, clear, complete, and constructive reports get higher ratings.

Scope

What’s in, what’s out

Disclosures are only eligible if they are in line with our defined scope.

In scope: https://*.on2it.net/ and https://*.on2it.nl/

Out of scope, no need to report:

The subdomains academy.on2it.net, zerotrust.on2it.net and feedback.on2it.net. SPF/DKIM/DMARC suggestions. Contact forms without submission limits. Known public files (e.g. robots.txt). Banner disclosure without PoC. Missing/lax security headers or Secure/HTTPOnly flags on non-sensitive cookies. WordPress wp-cron.php availability, we have controls in place. Informational disclosures about software versions, including WordPress core/theme/plugins.

Privacy

Minimum data, maximum care

As ON2IT B.V., a European company based in the Netherlands, we apply the highest standard of data protection based on the GDPR. We keep the minimum amount of information about you, for a limited time, and only for the sole purpose of communicating with you.

When you report a vulnerability we only collect your name (or pseudonym) and email address. If you qualify to be registered in our Hall of Fame, we’ll request your consent to register your name there. See our privacy policy for the full picture.

Found something?

Disclose it responsibly

Send us your report and a way to reproduce it. We’ll take it from there, rate it, fix it, and pay you out for the work.

responsibledisclosure@on2it.net Trust Center