Responsible Disclosure Policy
At VITO, we consider the security of our information and systems to be extremely important. Despite our efforts to secure our systems, it is possible that a vulnerability may nevertheless exist.
If you have discovered a vulnerability in one of our systems, we would like to hear from you so that we can take appropriate measures as quickly as possible. We would like to work with you to better protect our information and systems.
We have therefore adopted a policy of coordinated vulnerability disclosure (also known as a ‘Responsible Disclosure Policy’), so that you can inform us when you discover a vulnerability.
This Responsible Disclosure Policy applies to all VITO systems. If you are unsure whether this policy applies, please contact us at responsibledisclosure@vito.be to seek clarification.
What we ask of you
If you discover a vulnerability in one of our systems, we ask you to:
- Report the vulnerability as soon as possible after discovering it. Please email your findings to responsibledisclosure@vito.be.
- Provide sufficient information to enable us to reproduce the vulnerability so that we can resolve the issue as quickly as possible. In most cases, the IP address or URL of the affected system and a description of the vulnerability will be sufficient, but more information may be required for more complex vulnerabilities.
- Provide your contact details so that VITO can contact you to work together towards a secure outcome. Please provide at least your name, email address and/or telephone number. You may report a vulnerability under a pseudonym, but please ensure that we can contact you if we have any additional questions.
- Confirm that you have acted, and will continue to act, in accordance with this Responsible Disclosure Policy.
Rules you must follow
We ask you to comply with the following rules:
- Do not disclose the vulnerability publicly until we have had the opportunity to remedy it. (See below for information on possible publication afterwards.)
- Do not exploit the vulnerability by unnecessarily copying, deleting, modifying or accessing data. For example, do not download more data than is necessary to demonstrate the vulnerability.
- Do not carry out any of the following actions:
- installing malware (such as a virus, worm, Trojan horse, etc.);
- copying, modifying or deleting data on a system;
- making changes to the system;
- repeatedly gaining access to the system or sharing access with others;
- using automated scanning tools;
- using so-called ‘brute-force’ techniques to gain access to systems;
- using denial-of-service attacks or social engineering (phishing, vishing, spam, etc.).
- Do not use attacks against physical security, social engineering, distributed denial-of-service attacks, spam or third-party applications.
- Delete all data obtained through the vulnerability immediately after reporting it.
- Do not carry out any actions that could potentially affect the proper functioning of the system, including its availability or performance, or the confidentiality and integrity of the data.
Activities carried out under this Responsible Disclosure Policy must be limited to conducting tests to identify potential vulnerabilities and sharing the resulting information with VITO.
If, after the vulnerability has been remediated, you wish to publish information about it, we ask that you notify us at least one month before publication via the email address above and give us the opportunity to respond. You may identify VITO, either directly or indirectly, in a publication only with our explicit written consent.
What we promise
- If you have complied with the above conditions of this Responsible Disclosure Policy and have not committed any other offences or breaches, we will not take legal action in relation to your report.
- We will respond to your report within a short period, where possible within five working days, with our assessment of the report and, where applicable, an expected date for resolving the issue.
- We will treat your report confidentially and will not share your personal data with third parties without your consent, unless this is necessary to comply with a legal obligation.
- We will keep you informed of the progress made in resolving the issue.
- We will endeavour to resolve all issues within a short period.
- We may choose to disregard reports that are of insufficient quality.
If you have any questions, please contact us at responsibledisclosure@vito.be.
If you are unsure whether this policy applies to your situation, please contact us at this email address first to request explicit permission.
We reserve the right to amend the contents of this policy at any time or to terminate the policy.
This text is a derivative work of ‘Responsible Disclosure’ by Floor Terra, used under a Creative Commons Naamsvermelding 3.0 licence