Our commitment
Despite our best efforts, our own systems may contain weaknesses. If you find one, we would rather hear it from you than read about it somewhere else. Report it to us privately and we will work with you to understand and fix it, and we will not pursue legal action against you for research carried out in line with this policy.
How to report
- Email support@chainsecurities.org with "Responsible disclosure" in the subject line.
- Send the report by email. If you need encryption, ask us first and we will provide a method.
- Write in English or Dutch.
Please include:
- the affected URL, host or component, and the date and time of your testing;
- enough detail to reproduce the issue — steps, requests, or a short proof of concept;
- your assessment of the impact;
- how you would like to be credited, if at all.
Rules we ask you to follow
Research within these limits is welcome. Going beyond them is not covered by this policy and may be unlawful.
- Do no more than is necessary to demonstrate the issue. Once you have a proof of concept, stop.
- Do not access, modify, download or delete data belonging to anyone else. If you encounter personal or client data, stop immediately, do not save it, and tell us in your report.
- No denial-of-service, load testing, or volumetric scanning.
- No social engineering, phishing or physical intrusion against our people, our clients or our suppliers.
- Do not install backdoors, persist access, or pivot to other systems.
- Do not publish the issue, or any client information you encounter, until we have fixed it and agreed timing with you.
- Test only assets that are in scope, and never a client's environment. Our clients' systems are not ours to authorise, and testing them without their own written permission is illegal.
Scope
In scope:
- This website: chainsecurities.org (including www.chainsecurities.org)
- Infrastructure and business accounts demonstrably belonging to Chain Cybersecurity
Out of scope:
- Any client system, tenant or environment
- Third-party services we merely use, such as our hosting, email or advertising platforms — report those to the provider concerned
- Findings with no demonstrable security impact, such as missing security headers on their own, cookie flags on non-sensitive cookies, version disclosure, clickjacking on pages without state-changing actions, self-XSS, absent rate limiting on non-sensitive endpoints, SPF, DKIM or DMARC configuration suggestions, and output from automated scanners without a working proof of concept
- Social engineering, and reports about the security of a browser or operating system rather than our site
What you can expect from us
- An acknowledgement within 3 business days.
- An assessment with our view of the severity and an indicative remediation timeline within 10 business days.
- Updates while we work on it, and confirmation when it is resolved. We aim to fix confirmed issues within 90 days, sooner where severity demands it.
- Credit in a public acknowledgement if you would like it, once the issue is fixed.
- No legal action for research that follows this policy, and no report to the authorities about you for it. If a third party brings a claim about activity that followed this policy, we will make clear that it was authorised.
We do not run a paid bounty programme. Reports are handled on the basis of mutual professional respect, and we will say thank you properly.
If you are our client
Clients with an active engagement should use their normal escalation contact rather than this address, so the report reaches the team already working with you. For a suspected active incident, mark your email "URGENT — INCIDENT" and we will treat it accordingly.