Responsible Disclosure Policy

Optimizing safety when it comes to the ICT systems is a top priority for Radancy NL. However, as such systems remain vulnerable, possible loopholes and weaknesses cannot be eliminated. Hence, we would love to hear from you if you have found a weakness in one of our ICT systems. We will handle the safety issues accordingly, and therefore we make use of the following policy:

What we ask of you:
To provide enough information to reproduce the safety issue, ensuring that Radancy NL can solve the problem quickly. More often than not, the IP-address or the URL of the ICT system and a description of the shortcoming(s) will be enough. However, when it is a more complex problem, an elaborate description could be necessary.

To not share the information regarding the safety issue until it has been solved.

To act responsibly and accordingly by not executing more than necessary actions required for the identification of the safety issue.


Please do report:

Please do not report:

Stolen/leaked credentials by other sites can be reported but won't have a monetary reward. We are not responsible for account credentials leaked on other sites or password managers. If you do believe the leak originates from our systems, please do report that!

Whatever you do, please avoid the following actions:

What you can expect:

When a shortcoming in one of the in-scope assets is reported accordingly to the above stated terms and conditions, Radancy NL will not articulate any legal consequences on the notifier. Radancy NL will process the report confidentially and no personal details without permission will be shared with third parties, unless this is a legal requirement. After consultation, Radancy NL can acknowledge you by publishing your name as the one who identified this particular safety issue.

You can submit your findings to responsible-disclosure@radancy.cloud