Coordinated Vulnerability Disclosure
At Refa ICT, the security of our systems and those of our customers is a top priority. Still, a vulnerability may slip through. Found one? We would like to hear about it, so we can take action as quickly as possible.
What we ask of you
Email your findings to [email protected]. Provide enough information for us to reproduce the issue: usually the URL or address of the affected system and a description of the vulnerability are sufficient. More complex vulnerabilities may require additional detail.
Leave your contact details (an email address or phone number is enough) so we can work with you towards a secure outcome. Reporting anonymously is possible, but in that case we cannot keep you informed about the follow-up.
Report the vulnerability as soon as possible after discovery, do not share information about the issue with others until it has been resolved, and do not perform any actions beyond what is necessary to demonstrate the vulnerability.
Please avoid the following actions
• Installing malware, ransomware or backdoors.
• Copying, modifying or deleting data in a system (a directory listing is an acceptable alternative).
• Making changes to the system.
• Repeatedly accessing the system or sharing access with others.
• Using brute force attacks, denial-of-service attacks or social engineering to gain access to systems.
• Physically attacking our premises or employees.
What we promise
We will confirm receipt of your report within 2 business days and respond substantively within 5 business days, including our assessment and an expected resolution date. We will keep you informed of the progress.
We treat your report confidentially and will not share your personal details with third parties without your consent, unless required by law. Reporting anonymously or under a pseudonym is possible.
If you have complied with the conditions in this policy, we will not take legal action against you in connection with the report. If you wish, we will credit you as the discoverer of the vulnerability in any communication about the issue.
Depending on the severity of the issue and the quality of the report, we may offer a suitable token of appreciation, at our discretion. The vulnerability must be genuine and not previously known to us.
Scope
This policy applies to systems and services owned and operated by Refa ICT. If you find a vulnerability in a system that we manage on behalf of a customer, please report it to us as well: we will coordinate the resolution with the customer concerned and, where relevant, with the vendor.
Vulnerabilities in third-party products fall outside this policy. Where possible, we will help you report these to the appropriate party.
Out of scope
We do not consider the following findings to be vulnerabilities within the meaning of this policy, unless you demonstrate a concrete, reproducible attack with actual impact:
• Unverified output from automated scanners or vulnerability scans.
• Missing or incomplete SPF, DKIM or DMARC records without a demonstrable abuse scenario.
• Missing security headers (such as CSP, X-Frame-Options or HSTS) without exploitable impact.
• Clickjacking on pages without sensitive actions.
• Outdated software versions or banner disclosure without a working proof of concept.
• Self-XSS or vulnerabilities that require physical access or a compromised victim device.
• Best practice recommendations, configuration suggestions or theoretical risks without demonstrated exploitability.
• Reports concerning social engineering, phishing or spam.
Reports on this list will not be processed substantively and are not eligible for a reward. We do not respond to requests for payment for such reports.
Handling
We aim to resolve vulnerabilities as quickly as possible, depending on their severity and complexity. We will coordinate with you on when and how the vulnerability will be published. Our starting point is publication after remediation, no later than 90 days after the report, unless we agree otherwise together.
This policy is based on the Coordinated Vulnerability Disclosure guideline published by the Dutch National Cyber Security Centre (NCSC-NL). Last updated: 01-07-2026.