Appfront develops software for clients in sectors including finance, healthcare and industry. Security is an ongoing responsibility, not a fixed state. We value the work of external researchers who help us find vulnerabilities before they can cause harm. This policy describes how you can report a vulnerability to us responsibly, what you can expect from us, and which legal frameworks apply.
We follow a coordinated vulnerability disclosure (CVD) model in line with the guidelines of the NCSC, the DIVD and ENISA. This means reporting, investigation and publication are coordinated, with the aim of fixing vulnerabilities as quickly as possible without needlessly endangering users, clients or third parties.
We do not take legal action against researchers who abide by the rules of this policy. We regard responsible reports as a service to us, our clients and the wider internet infrastructure. If you have questions about how this policy applies to a specific piece of research, you can raise them in advance with security@appfront.nl.
This policy is a living document. We update it when laws and regulations, infrastructure or insights into security research require it. Changes are published on this page, with the version date stated. For clients and auditors who wish to cite this policy in a vendor onboarding or risk assessment, the version shown on this page at the time of consultation applies.