Responsible disclosure
We consider the security and data of our systems a top priority. Since we are committed to system security, we understand and appreciate the added value of security researchers who help us improve.
Find a vulnerability? Disclose it responsibly, we’ll listen, rate it, fix it, and reward you.
Program rules
In order to protect our systems and users, we’ve compiled a short list of rules regarding vulnerability disclosure. Following them keeps your report processable and rewardable.
Only systems within our scope are applicable. Report the vulnerability as quickly as possible after discovery. Use your own data (name, email address) to demonstrate the issue; pseudonyms are fine.
Don’t take advantage of the issue, no downloading more data than necessary, no deleting or modifying anyone’s data, no installing malware, no system changes. Demonstrate, don’t exploit.
Don’t reveal the problem until it’s resolved. Provide enough information to reproduce it, a Proof-of-Concept is ideal. For duplicate reports, only the first one received is awarded, provided it can be reproduced.
We ask that all disclosures are kept confidential to protect our community. For major disclosures, a joint public statement may be possible, but this must be agreed beforehand via responsibledisclosure@on2it.net.
Rated, ranked, and paid out
All responsible disclosures are rated by our security professionals to calculate a possible reward. Rewards are paid out using the Tremendous platform. Five criteria drive the rating.
Reproducibility
Reproducibility and verifiability of the vulnerability. Without it, we can’t confirm or fix it.
Severity
Severity of the vulnerability disclosed. Higher impact = higher rating.
Exploitability
Likelihood that the vulnerability would have been exploited in the wild before disclosure.
Asset criticality
Criticality of the assets affected by the vulnerability, what was at stake.
Communication
Quality of the communication, clear, complete, and constructive reports get higher ratings.
What’s in, what’s out
Disclosures are only eligible if they are in line with our defined scope.
In scope: https://*.on2it.net/ and https://*.on2it.nl/
Out of scope, no need to report:
The subdomains academy.on2it.net, zerotrust.on2it.net and feedback.on2it.net. SPF/DKIM/DMARC suggestions. Contact forms without submission limits. Known public files (e.g. robots.txt). Banner disclosure without PoC. Missing/lax security headers or Secure/HTTPOnly flags on non-sensitive cookies. WordPress wp-cron.php availability, we have controls in place. Informational disclosures about software versions, including WordPress core/theme/plugins.
Minimum data, maximum care
As ON2IT B.V., a European company based in the Netherlands, we apply the highest standard of data protection based on the GDPR. We keep the minimum amount of information about you, for a limited time, and only for the sole purpose of communicating with you.
When you report a vulnerability we only collect your name (or pseudonym) and email address. If you qualify to be registered in our Hall of Fame, we’ll request your consent to register your name there. See our privacy policy for the full picture.
Disclose it responsibly
Send us your report and a way to reproduce it. We’ll take it from there, rate it, fix it, and pay you out for the work.