Security Vulnerability Disclosure Program

We do our utmost to ensure the security of this website and the projects we deliver, keeping them up to date with the latest security standards. Have you discovered a security vulnerability? Here you can find how to report it to us.

Why report here?

Our projects are used every day in real-world scenarios and by actual organizations, meaning that the potential impact of misuse can be significant for both us and our clients.

We therefore ask you to act responsibly and ethically when reporting potential security issues. Please do not share these vulnerabilities with others. Instead, follow the steps outlined below.

Which software does this apply to?

This applies to this website and other projects that we develop and/or maintain, either fully or partially. In most cases, this applies when you can find our logo or company name in the footer of the website.

If your report turns out not to apply to us (for example, because we no longer maintain the project), you can still rely on us to act responsibly. We will do our best to put you in contact with the appropriate party who can take further action.

What should and should not be done?

If possible, avoid making any changes. In some cases, changes may be necessary to properly demonstrate the issue. If so, please follow these guidelines:

  • Do not perform actions that could potentially disrupt the general operation of the website.
  • Do not delete or modify data belonging to other users.
  • Do not delete or modify data if you suspect the changes cannot be reversed.
  • Only access the minimum amount of data required to demonstrate the vulnerability. Limit the impact of your testing as much as possible.
  • Do not share information about the vulnerability on social media or with third parties.
  • Do not perform DDoS attacks or social engineering attempts. These activities are not covered by this program.

What should I do after discovering a vulnerability?

Report security vulnerabilities by sending an email to info@inventis.be. Please include the following information:

  • Where did you discover the vulnerability? Include the URL of the affected page, or the homepage if this does not apply.
  • Which specific steps can be taken to reproduce the issue (for example, starting from opening the homepage)?
  • If you know it, include the date and time when you discovered or reproduced the issue.

Suggestions for a suitable solution or improved approach are appreciated, but they are not required.

We will review your email as soon as possible and aim to respond within a few working days regarding further follow-up.

Can I report anonymously?

Yes. You can send a report from a temporary or anonymous email address. However, in that case we will not be able to request additional information, thank you personally, or provide a possible reward.

Please make sure your report contains all relevant information.

A big thank you to all anonymous reporters ☺!

Do you offer rewards?

Sometimes. We assess this on a case-by-case basis. Not every reported issue automatically qualifies for a reward.

One possible reward we may provide is authentic Inventis honey, handcrafted by our company beekeeper and cared for by our Inventis bees!

Where can I find more information?

Do you have any questions that are not answered above? You can always contact us at info@inventis.be for more information about security within our projects or our security program.