If you find a weak spot in this website, please send an email with the information to responsibledisclosure@kiwa.nl.
Report the vulnerability before you inform others. This will allow Kiwa Register to take immediate appropriate measures. This is called responsible disclosure.
What you should consider with responsible disclosure
When you report a vulnerability, keep some of the following issues in mind:
- Provide enough information to replicate the problem. This will allow us to solve the problem as quickly as possible. Usually it's enough to provide us with the IP address or URL of the affected system and a description of the vulnerability. In case of more complex vulnerabilities we may need more information.
- Please provide your contact information (email address or phone number) so we can contact you.
- If you discover a vulnerability, please notify us as quickly as possible.
- Don't share any information about the security problem with others until it is completely resolved.
- Please handle the knowledge about the security issue responsibly. Do not take any action beyond what is necessary to demonstrate the vulnerability.
Does your report comply with these conditions? In that case Kiwa Register will not undertake any legal actions regarding the notification.
Never misuse a weak spot in an ICT system
If you have discovered a vulnerability, don't misuse this by doing any of the following:
- place malware;
- copy, change or delete information in a system (an alternative for this is making a directory listing of a system);
- introduce changes to the system;
- obtain repeated access to the system or share access with others;
- use so-called brute force to access systems;
- use denial-of-service or social engineering.
Did you report a weak spot in an ICT system? Your report will be addressed as follows:
- Kiwa Register responds as quickly as possible to the report. The response includes an assessment of the report and an expected resolution date.
- Kiwa Register will keep you informed of the progress.
- Kiwa Register will resolve the security problem as quickly as possible. A notification will only be issued after the problem has been resolved.
- Kiwa Register will treat your report with confidentiality. We do not share your personal information with third parties without your permission, unless we are legally obligated or mandated by a court of law to do so.