generated: '2026-09-02' method: searched source: https://www.code24.nl/kwetsbaarheid-melden program: name: Coordinated Vulnerability Disclosure (Kwetsbaarheid melden) published: true url: https://www.code24.nl/kwetsbaarheid-melden language: nl last_updated: '2023-01' http_status: 200 bug_bounty: false platform: null note: >- A self-hosted CVD policy page, not a bug-bounty programme and not an RFC 9116 security.txt. /.well-known/security.txt returns 404 on every CODE24 host; a /securitytxt page exists on the site but its body contains only the words "security.txt". contact: email: securityofficer@code24.nl pgp: true pgp_key_published_inline: true pgp_key_uid: Securityofficer Code24 pgp_fingerprint: 808463365234FAC600E5F3D65FF8001446902779 pgp_algorithm: EdDSA (Ed25519), created 2022-10-24 pgp_note: >- An ASCII-armoured public key block is published inline on the disclosure page. The fingerprint above was computed here (SHA-1 over the v4 public-key packet) from that published block on 2026-09-02; it is recorded for identification only and is not a substitute for verifying the key out of band. The key block itself is not copied into this repo. commitments: - Initial response with an assessment and an expected fix date within three days. - No legal action against reporters who follow the stated conditions. - Reports handled confidentially; personal data not shared with third parties without consent. - Reporter kept informed of remediation progress. - Public credit to the reporter by name on request. reporter_conditions: - Do not exploit the finding beyond what is needed to demonstrate it; do not download excess data or read, delete or modify third-party data. - Do not disclose to others until fixed, and erase any confidential data obtained. - No physical attacks, social engineering, DDoS, spam, or attacks on third-party applications. - Provide enough information to reproduce (typically the IP address or URL plus a description). scope: in_scope: - Domains ending in code24.nl - CODE24 websites and software out_of_scope: - Any system on a domain other than code24.nl - SPF/DMARC record findings - (D)DoS and rate-limiting of calls - Self-XSS - Error messages without sensitive data - Reports that merely disclose which software CODE24 uses - Complaints, website-availability reports, phishing e-mail reports, and fraud reports