Last updated: September 2026
We test other organizations’ systems for a living, so ours should face the same scrutiny. If you find a weakness in something we run, we want to hear it from you before anyone else does. This page sets out what you can test, how to reach us, and what we promise in return.
Scope
skuridat.comand all of its subdomains- The platform we use to run assessments, and any client portal we operate
- Any other internet-facing system that Skuridat operates itself
If you’re unsure whether something is ours, ask at [email protected] before you test it.
Out of scope
- Our clients’ systems, even if you found them through us. Report those to the organization itself. If you can’t reach them, NCSC-NL can help you get the report to the right place.
- Third-party services we use, such as our hosting, email and CRM providers, unless the issue is in how we configured them. Flaws in the product itself belong with the vendor.
- Denial of service, load testing, or anything else that degrades the service for other people.
- Social engineering or phishing of our staff, clients or suppliers, and physical attacks on our offices.
- Flooding our forms or mailboxes.
- Scanner output with no demonstrated impact: missing security headers, version banners, SPF, DKIM or DMARC settings, self-XSS, clickjacking on pages with no state-changing action, and TLS configuration notes.
How to report
Email [email protected]. If the report contains anything sensitive, encrypt it with our PGP key.
PGP fingerprint: 7508 B0E9 AEF7 5E4E 2928 5149 37F7 C998 1B36 F20B
The public key is on keys.openpgp.org under [email protected]. Check the fingerprint above before you use it.
A useful report tells us:
- which asset is affected (URL, hostname or IP address)
- the steps to reproduce, and any proof-of-concept
- what an attacker could gain
- whether you’ve told anyone else
- how you’d like to be credited, or that you’d rather stay anonymous
One issue per report. English, Dutch and Portuguese are all fine.
What we commit to
- We acknowledge your report within two working days.
- We give you our assessment within ten working days: valid, duplicate, out of scope, or accepted risk, with our reasons.
- We keep you updated while we fix it, and tell you when it’s done.
- We aim to fix valid issues within 90 days. If we need longer, we say so and explain why.
- We credit you by name or handle when we publish the fix, unless you ask us not to.
- We don’t take legal action against research that follows this policy (see Safe harbor below).
What we ask of you
- Don’t access, change or delete data that isn’t yours. If you reach someone else’s data, stop, tell us what you saw, and delete anything you kept.
- Don’t exfiltrate data to prove a point. A screenshot showing a record count is enough.
- Don’t install backdoors, create persistent accounts, or move further into our systems than you need to demonstrate the issue.
- Keep automated tools to a rate that doesn’t affect other users.
- Give us time to fix the issue before you disclose it. We suggest 90 days from your report, and we’re happy to agree a date together.
- Stay within the scope above.
Safe harbor
If you act in good faith and within this policy, we consider your research authorized. We won’t file a police report against you or bring a civil claim.
We can’t bind the Dutch Public Prosecution Service (Openbaar Ministerie), which makes its own decisions. The prosecution service does take a published disclosure policy into account, and if it or anyone else asks, we’ll confirm on the record that you worked within ours. The same goes for a third party that brings a claim against you over research that stayed inside this policy.
Rewards
We don’t run a paid bug bounty. We offer public credit, a written thank you, and a straight account of what we changed. If that changes, this page will say so.
A machine-readable version of our contact details is published at /.well-known/security.txt.