Responsible Disclosure
Last updated: 19 August 2026
We take the security of our systems and our customers’ data seriously. If you nevertheless discover a vulnerability, we would like to hear about it as soon as possible so we can fix it. This policy describes how to report a vulnerability and what you can expect from us.
1. Reporting a vulnerability
Send your report to [email protected] as soon as possible after discovery, with the subject “Responsible disclosure”. Please include:
- a description of the vulnerability and its potential impact;
- the steps to reproduce the issue (URL, configuration, time of your research);
- any supporting evidence, such as screenshots;
- your contact details, so we can reach you about the follow-up. We also take anonymous reports seriously.
2. Rules of engagement
We ask you to:
- not share the vulnerability with others until it has been fixed;
- not go further than strictly necessary to demonstrate the vulnerability;
- not view, copy, modify or delete data that is not yours — a directory listing or minimal proof is sufficient;
- not use (D)DoS attacks, brute-force attacks, spam, social engineering or physical attacks;
- not leave backdoors, malware or self-created accounts in our systems;
- act proportionately and stop your research immediately once the vulnerability has been demonstrated.
This policy is not an invitation to actively scan our systems for weaknesses at scale; we monitor our infrastructure ourselves.
3. What you can expect from us
- You will receive an acknowledgement of receipt within three (3) working days.
- Within seven (7) working days of the acknowledgement, you will receive our assessment of the report and, where possible, an expected timeline for the fix.
- We treat your report confidentially and do not share your details with third parties without your consent, unless we are legally required to do so.
- If you act in accordance with this policy and the Belgian legal framework (see section 5), we will not take legal action against you in response to your report.
- Together with you, we determine whether and how the vulnerability is communicated after it has been fixed. If you wish, we will credit you as the discoverer.
We do not run a bug bounty programme and do not offer financial rewards by default; for valuable reports we are happy to show our appreciation.
4. Scope
This policy applies to the website dijiweb.be and the subdomains and systems managed by DIJIWEB itself.
Out of scope are, among others:
- the systems of our hosting partner platform Servitus (servitus.nl) — report vulnerabilities there directly through their own disclosure policy;
- third-party services we rely on but do not manage ourselves;
- reports without security impact, such as the website being unavailable, phishing emails abusing our name, or fraud — please use the contact form for those.
5. Belgian legal framework
Belgium has a legal framework for reporting vulnerabilities, coordinated by the Centre for Cybersecurity Belgium (CCB). To qualify for legal protection you must, among other things, act without fraudulent intent or intent to cause harm, act proportionately, report without undue delay to the organisation concerned and to the CCB, and not disclose the vulnerability publicly without the CCB’s consent. The current procedure and conditions can be found at ccb.belgium.be.