Policy · Security

Coordinated vulnerability disclosure policy.

Have you found a vulnerability in an Appfront system or service? Report it to us through a coordinated process. We handle every serious report confidentially, thank good-faith researchers and do not take legal action against responsible disclosures that remain within this policy.

Policy typeCVD / Responsible disclosure
Reporting channelsecurity@appfront.nl
PGPOn request
AcknowledgementWithin 5 working days
DisclosureCoordinated
VersionMay 2026

Our commitment to researchers.

Appfront develops software for clients in sectors including finance, healthcare and industry. Security is an ongoing responsibility, not a fixed state. We value the work of external researchers who help us find vulnerabilities before they can cause harm. This policy describes how you can report a vulnerability to us responsibly, what you can expect from us, and which legal frameworks apply.

We follow a coordinated vulnerability disclosure (CVD) model in line with the guidelines of the NCSC, the DIVD and ENISA. This means reporting, investigation and publication are coordinated, with the aim of fixing vulnerabilities as quickly as possible without needlessly endangering users, clients or third parties.

We do not take legal action against researchers who abide by the rules of this policy. We regard responsible reports as a service to us, our clients and the wider internet infrastructure. If you have questions about how this policy applies to a specific piece of research, you can raise them in advance with security@appfront.nl.

This policy is a living document. We update it when laws and regulations, infrastructure or insights into security research require it. Changes are published on this page, with the version date stated. For clients and auditors who wish to cite this policy in a vendor onboarding or risk assessment, the version shown on this page at the time of consultation applies.

security@
Central reporting channel for vulnerabilities
PGP
Encryption supported, fingerprint on request
Safe harbour
No legal action for responsible research
Hall of Fame
Public recognition for reporters, if desired

Scope: what falls under this policy?

01
In scope

appfront.nl and subdomains

The public production website, marketing subdomains and publicly accessible applications operated by Appfront B.V. This also includes API endpoints and authentication flows on these domains.

02
In scope

Infrastructure managed by Appfront

Cloud environments, build pipelines and deployment channels managed by us for our own services. Including publicly accessible configuration or supply-chain components that directly affect our software.

03
Out of scope

Client systems and third-party SaaS

Systems belonging to our clients (even where we built them) fall under that client's policy. Third-party services such as Google Workspace, HubSpot or GitHub fall under that provider's policy.

04
Out of scope

Non-public and test environments

Internal endpoints that are not publicly reachable, staging environments behind authentication, and local development environments are out of scope, unless you have inadvertently gained access and report this to us yourself.

Which types of vulnerability do we welcome?

Category 01

OWASP Top 10 classes

Injection (SQL, command, LDAP), broken access control, broken authentication, server-side request forgery, insecure deserialisation and all other vulnerability classes from the current OWASP Top 10 for web and API.

Category 02

Authentication and authorisation

Authentication bypass, session management flaws, privilege escalation, multi-tenancy leaks, IDOR vulnerabilities and weaknesses in two-factor or single sign-on implementations on systems managed by us.

Category 03

Supply chain and infrastructure

Vulnerable or misconfigured dependencies, insecure build or release pipelines, leaks of credentials or secrets in public artefacts, and infrastructure misconfigurations that enable exploitation.

What we ask of you as a researcher.

Responsible research protects both you and our users. Please follow the rules below, so that your research remains within policy and within the legal framework of acting in good faith under, among other things, the ISO 27001 guidelines that we follow.

No DoS or denial of service

No load testing, no flooding, and no tests that affect availability.

No mass scanning

No high-frequency automated scans or broad payload sets.

Do not exfiltrate customer data

A proof of concept is sufficient. Stop once you have obtained the minimum evidence needed.

No social engineering

No phishing or pretexting of employees, customers or suppliers.

No physical attacks

No attempts to gain access to offices, data centres or equipment.

Respect privacy

Do not view, copy or store personal data belonging to third parties.

No backdoors

Do not leave backdoors, malware or persistence in our systems.

Confidential

Do not disclose the finding publicly until we have jointly agreed on a date.

How to report to us.

Step 01 · Send the report

Email to security@appfront.nl

Email your finding to security@appfront.nl. For sensitive content, you can request our PGP fingerprint and encrypt your message. For urgent matters, you may simultaneously copy fabian.vandijk@appfront.nl.

Step 02 · What it should contain

Reproducible description

Provide a clear description of the vulnerability, reproducible steps, the impact you estimate, any screenshots or log entries, and a suggestion for mitigation. Please also state whether you wish to be publicly acknowledged.

Step 03 · Initial response

Confirmation within 5 working days

You will receive an initial confirmation from our security team within five working days. We will validate the finding, determine its severity, and agree with you how we will keep you informed of progress up to publication.

What you can expect from Appfront.

01
Acknowledgement

Initial response within 5 working days

An acknowledgement of receipt with an initial assessment of severity. For serious findings we generally respond more quickly. No automated no-reply.

02
Progress

Updates tailored to severity

We will keep you informed of the progress of the investigation and the fix. There are no predetermined deadlines: pace and details depend on impact, complexity and dependencies on third parties.

03
Disclosure

Coordinated publication

Publication only takes place once the fix is live in production. In line with international practice, we apply a reasonable period after confirmation, with room to deviate by mutual agreement for complex chains.

04
Acknowledgement

Hall of Fame, if desired

Researchers who have helped us and would like public recognition will be listed in our Hall of Fame on this page. You may also remain anonymous; we respect your choice.

Legal and normative framework.

Framework 01

Good-faith research

Article 138ab of the Dutch Criminal Code (computer trespass) does not rule out responsible security research where it is proportionate, purpose-driven and reported. Research carried out within the rules of this policy will not lead to a report to the police by Appfront.

Section 02

NIS2 and the Dutch Cybersecurity Act

The Dutch Network and Information Systems Security Act (Wbni) and the European NIS2 Directive require appropriate security measures and reporting of serious incidents. A coordinated vulnerability disclosure process is a logical part of that.

Section 03

GDPR and DORA

For reports involving personal data, we follow Articles 33 and 34 of the GDPR on personal data breach notification. For financial sector clients, the European DORA Regulation is relevant; where applicable, we align with it and coordinate timelines and communication with supervisory authorities.

How we handle reports internally.

A report received at security@appfront.nl is read only by staff involved in handling it. We apply a need-to-know principle: technical details are shared only with colleagues or clients who need them to validate, reproduce and fix the vulnerability.

After initial validation, we classify the finding by severity (low, medium, high, critical) and by responsible owner. For our own systems, we schedule the fix based on that classification. For findings that affect a client or sit with a client's system, we inform the client confidentially within our contractual arrangements and coordinate with them rather than publishing unilaterally.

Communication with the reporter takes place in the same email thread, preferably in the language of the original report. For critical findings, we may ask you to be available for a brief technical verification. Once a fix has been rolled out, you will be informed, and we will discuss any coordinated publication.

What applies to specific situations?

Not every case is the same. The overview below helps you assess where your finding fits within this policy and what a reasonable next step is.

Active exploitation observed

Report it immediately, including outside office hours. We escalate internally to incident response.

Finding in a client system

We inform the relevant client confidentially and coordinate with them.

Personal data encountered

Do not keep or share anything, and mention it in your report. We will assess the GDPR impact together.

Unintentionally gained access

Stop immediately, do not collect further data, and report it. No sanction for good-faith actions.

Bug bounty platform

Appfront does not currently operate a bug bounty platform; we accept direct reports.

Cash bounty

We do not normally offer cash rewards; for exceptional impact, we will discuss tailored recognition.

Press or third parties

Refer enquiries to security@appfront.nl. We keep communication coordinated.

Compliance auditor

Clients and auditors may cite this policy as evidence during vendor onboarding.

Hall of Fame.

Open invitation

Place reserved for the first reporter

We are glad to acknowledge by name or pseudonym the researchers who have helped us, once the first responsible disclosure has been handled and the reporter wishes to receive public recognition.

Anonymous possible

Acknowledgement on your terms

You decide whether your contribution is visible and under which name. We do not credit researchers without their explicit consent and keep disclosed information to a minimum.

Coordination

In line with the NCSC and DIVD

For reports received through a coordinating body, such as the NCSC or DIVD, we follow their acknowledgement and communication protocols and align our publication accordingly.

Frequently asked questions.

What exactly is a CVD policy?
A coordinated vulnerability disclosure (CVD) policy sets out how an organisation wants external researchers to report vulnerabilities, how it responds to those reports, and how publication is handled. It is a practical application of the international responsible disclosure standard recommended by bodies such as the NCSC and ENISA. The aim is for flaws to be fixed before they can be exploited, without the reporter facing legal consequences.
Who can report a vulnerability to Appfront?
Anyone: independent security researchers, students, customers, suppliers, other agencies or members of the public who happen to find a flaw. You do not need any relationship with Appfront to benefit from the safe harbour of this policy. We do ask that you follow the ground rules set out above and direct your report to us immediately and exclusively, rather than to third parties or the press.
Do I have to give my name when I report?
No. You may report under a pseudonym or completely anonymously. Please be aware that anonymous reports make it harder for us to ask clarifying questions or keep you updated on progress. We keep contact details to a minimum, use them only to handle your report, and do not publish your identity without your explicit consent.
Will I receive a cash bug bounty?
By default, Appfront recognises contributors rather than paying a cash bounty. We do not currently have a fixed amount per severity category. For findings of exceptional impact, we will agree a tailored form of recognition by mutual consent. What we always offer is confidential handling, a serious and substantive dialogue, and public credit on our Hall of Fame if you wish.
How long does it take for a fix to go live?
That depends on the severity, the nature of the vulnerability and any dependencies on third parties. A misconfiguration in our own systems can often be resolved quickly; a supply-chain issue involving several parties takes longer. We work to a reasonable timeframe before publication, in line with international CVD practice, and will agree a deviation where complexity requires it or where active exploitation is taking place.
May I publish about the finding myself?
Yes, but only once we have jointly agreed a date and the fix is live. Premature publication without coordination falls outside the scope of this policy and can worsen the risk position of customers or end users. We are happy to work with you on a joint advisory or coordinated post in which your research and our remediation are published together.
Which customers or auditors ask for a CVD policy?
Mainly financial institutions, healthcare providers, semi-public organisations and large corporates ask during vendor onboarding whether a supplier has a demonstrable CVD or responsible disclosure process. For customers with ISO 27001, NEN 7510, SOC 2 or DORA obligations, this policy is relevant material for their own compliance file.
Does this policy also apply to software Appfront built for my organisation?
Not automatically. Bespoke software we build for clients typically runs under the responsibility and within the infrastructure of that client. This means their own security policy and reporting process take precedence. Where helpful, we assist our clients in setting up their own CVD policy; please get in touch via /contact.

Found a vulnerability?

Send your report to security@appfront.nl. We handle every serious report confidentially and confirm receipt within five working days. For encrypted communication, you can request our PGP fingerprint at the same address.

Confirmation within 5 working days
Confidential handling
Westerdoksdijk 599, Amsterdam

Edit content