1. Reporting Vulnerabilities
Security researchers and users are encouraged to report potential security vulnerabilities to security@apptimate.nl. Apptimate B.V. will make reasonable efforts to acknowledge reports within five (5) business days and to investigate reported vulnerabilities in a timely manner.
2. Responsible Disclosure
We operate a responsible disclosure policy. We ask reporters to treat vulnerabilities confidentially and to allow us a reasonable period to resolve them before any information is made public.
3. Rules for Researchers
- Do not access, store, or modify other users' data.
- Do not disrupt the service and do not perform denial-of-service attacks.
- Do not disclose vulnerabilities before Apptimate B.V. has had a reasonable opportunity to resolve them.
- Act in good faith and stay within the limits of the law.
4. No Legal Action
Apptimate B.V. will not pursue legal action against researchers who act in good faith and comply with this policy.
5. Hall of Fame
Upon request and at its discretion, Apptimate B.V. may acknowledge reporters who have contributed responsibly in a “Hall of Fame”.
6. What to Report
- A clear description of the vulnerability.
- Steps to reproduce the vulnerability.
- The potential impact and, if available, a proposed mitigation.
7. Contact
- Security: security@apptimate.nl