We take the security of our own systems seriously. Even so, despite all
care, there may be a weak spot somewhere. If you discover such a
vulnerability in one of our systems, we appreciate it if you let us know
before others abuse it. This is called responsible disclosure or
coordinated vulnerability disclosure.
Because our work revolves around finding vulnerabilities, we know better
than anyone how valuable a good report is.
What does this policy apply to?
This policy applies to the systems that Hackify manages itself:
- hackify.nl and its subdomains;
- pentests.nl and phishify.nl;
- the other websites and applications managed by Hackify;
- Hackify’s infrastructure and networks.
Out of scope:
- third-party services that we use but do not host ourselves (for
example our collaboration, mail and CRM providers; report findings
there directly to the provider concerned);
- social engineering aimed at our staff;
- physical security of our locations;
- attacks on the availability of systems, such as denial-of-service.
Not sure whether something is within scope? Contact us first via
[email protected] before you continue.
What do we ask of you?
To keep a report responsible, we ask you to observe these principles:
- report the vulnerability as soon as possible after you discover it;
- provide enough information to reproduce the problem (system involved,
steps, possibly a proof-of-concept);
- do no more than necessary to demonstrate the vulnerability, and stop
as soon as you have the evidence;
- do not view other people’s data and do not change or delete any data;
- if you did view or download data during your research, delete it
immediately after you have been able to demonstrate your finding, and
mention this in your report;
- do not use automated scanners without coordinating with us in
advance, and do not carry out brute-force or denial-of-service
attacks;
- do not share the vulnerability with others and do not make it public
while it has not yet been resolved.
If you observe these principles, we consider your actions to be in good
faith.
What can you expect from us?
If you report a vulnerability in accordance with this policy, we commit
to the following:
- you receive confirmation within three working days that we have
received your report;
- you receive a status update at least every two weeks until the
vulnerability is resolved or we agree otherwise with you;
- we treat your report and your data confidentially and do not share
your data with third parties without your consent;
- we keep you informed of when the vulnerability has been fixed;
- with your consent we mention your name or pseudonym as thanks for
your contribution, after the vulnerability has been resolved;
- we take no legal action against you and file no report to the
authorities, as long as you have observed this policy.
We aim for resolution and public disclosure within a reasonable period
determined by mutual agreement, based on severity and complexity. As a
general guideline we use a target of 90 days for public disclosure
(industry standard), shorter in cases of high urgency or longer if a fix
verifiably requires more time.
How do you report a vulnerability?
Send your report by email to [email protected]. Our contact details
are also in our security.txt on our domains
(RFC 9116).
A useful report includes at least:
- a description of the vulnerability and its type (for example
cross-site scripting, SQL injection, IDOR, RCE);
- the system, URL or endpoint concerned;
- clear steps that allow us to reproduce the problem, possibly with
examples or screenshots;
- a brief assessment of the impact, in other words what an attacker
could do with it;
- your contact details so we can consult with you, and whether you would
like to be named in any acknowledgement.
We ask you not to send along any sensitive data of others. A
description of the vulnerability is sufficient.
If we cannot resolve it together, or if you prefer to report via an
independent third party, you can contact the DIVD (Dutch Institute for
Vulnerability Disclosure, https://divd.nl) or a similar coordinating
organisation. We are happy to cooperate with a coordinated report.
A note on rewards
Hackify does not have a formal bug bounty program. We do this work
because we consider the security of our systems important, not to pay
out a reward. For a valuable report we are happy to thank you with an
acknowledgement (security.txt acknowledgements or a separate
hall-of-fame page). We assess case by case whether a token of
appreciation is appropriate. A report does not create any right to a
reward.
Hall of fame
With thanks to the researchers who have contributed to the security of
our systems through responsible disclosure.
- Harsh Maheta — deprecated TLS 1.1 support with a weak cipher suite on hackify.nl (July 2026, resolved).
Questions
Do you have a question about this policy, or would you like to consult
us before doing research? Feel free to contact us via
[email protected].
For complaints about our services, we refer you to our
complaints policy. For how we handle
personal data, see our privacy statement.