Monthly vulnerability scanning: first month free! Learn more →
Hero

WE ARE

HACKIFY

Responsible Disclosure

We take the security of our own systems seriously. Even so, despite all care, there may be a weak spot somewhere. If you discover such a vulnerability in one of our systems, we appreciate it if you let us know before others abuse it. This is called responsible disclosure or coordinated vulnerability disclosure.

Because our work revolves around finding vulnerabilities, we know better than anyone how valuable a good report is.

What does this policy apply to?

This policy applies to the systems that Hackify manages itself:

  • hackify.nl and its subdomains;
  • pentests.nl and phishify.nl;
  • the other websites and applications managed by Hackify;
  • Hackify’s infrastructure and networks.

Out of scope:

  • third-party services that we use but do not host ourselves (for example our collaboration, mail and CRM providers; report findings there directly to the provider concerned);
  • social engineering aimed at our staff;
  • physical security of our locations;
  • attacks on the availability of systems, such as denial-of-service.

Not sure whether something is within scope? Contact us first via [email protected] before you continue.

What do we ask of you?

To keep a report responsible, we ask you to observe these principles:

  • report the vulnerability as soon as possible after you discover it;
  • provide enough information to reproduce the problem (system involved, steps, possibly a proof-of-concept);
  • do no more than necessary to demonstrate the vulnerability, and stop as soon as you have the evidence;
  • do not view other people’s data and do not change or delete any data;
  • if you did view or download data during your research, delete it immediately after you have been able to demonstrate your finding, and mention this in your report;
  • do not use automated scanners without coordinating with us in advance, and do not carry out brute-force or denial-of-service attacks;
  • do not share the vulnerability with others and do not make it public while it has not yet been resolved.

If you observe these principles, we consider your actions to be in good faith.

What can you expect from us?

If you report a vulnerability in accordance with this policy, we commit to the following:

  • you receive confirmation within three working days that we have received your report;
  • you receive a status update at least every two weeks until the vulnerability is resolved or we agree otherwise with you;
  • we treat your report and your data confidentially and do not share your data with third parties without your consent;
  • we keep you informed of when the vulnerability has been fixed;
  • with your consent we mention your name or pseudonym as thanks for your contribution, after the vulnerability has been resolved;
  • we take no legal action against you and file no report to the authorities, as long as you have observed this policy.

We aim for resolution and public disclosure within a reasonable period determined by mutual agreement, based on severity and complexity. As a general guideline we use a target of 90 days for public disclosure (industry standard), shorter in cases of high urgency or longer if a fix verifiably requires more time.

How do you report a vulnerability?

Send your report by email to [email protected]. Our contact details are also in our security.txt on our domains (RFC 9116).

A useful report includes at least:

  • a description of the vulnerability and its type (for example cross-site scripting, SQL injection, IDOR, RCE);
  • the system, URL or endpoint concerned;
  • clear steps that allow us to reproduce the problem, possibly with examples or screenshots;
  • a brief assessment of the impact, in other words what an attacker could do with it;
  • your contact details so we can consult with you, and whether you would like to be named in any acknowledgement.

We ask you not to send along any sensitive data of others. A description of the vulnerability is sufficient.

Mediation

If we cannot resolve it together, or if you prefer to report via an independent third party, you can contact the DIVD (Dutch Institute for Vulnerability Disclosure, https://divd.nl) or a similar coordinating organisation. We are happy to cooperate with a coordinated report.

A note on rewards

Hackify does not have a formal bug bounty program. We do this work because we consider the security of our systems important, not to pay out a reward. For a valuable report we are happy to thank you with an acknowledgement (security.txt acknowledgements or a separate hall-of-fame page). We assess case by case whether a token of appreciation is appropriate. A report does not create any right to a reward.

Hall of fame

With thanks to the researchers who have contributed to the security of our systems through responsible disclosure.

  • Harsh Maheta — deprecated TLS 1.1 support with a weak cipher suite on hackify.nl (July 2026, resolved).

Questions

Do you have a question about this policy, or would you like to consult us before doing research? Feel free to contact us via [email protected].

For complaints about our services, we refer you to our complaints policy. For how we handle personal data, see our privacy statement.