Responsible disclosure

If you've found a security issue in something of mine, I want to hear about it. This page says what I commit to and what I ask in return.

How to report

securityREMOVE@handsonzero.com

Include enough for me to reproduce it: what you did, what happened, and what you expected instead. A proof of concept helps. Rough notes are fine. I'd rather have a scrappy report today than a polished one in a month.

Scope

In scope: systems that are mine.

  • handsonzero.com and handsonzero.nl, including subdomains
  • The mail configuration for both domains
  • Code I publish publicly

Out of scope: client systems. If you've found something in a system I've tested for someone else, report it to them. I have no authority to accept or act on a report about another organisation's infrastructure.

Also out of scope: missing security headers with no demonstrated impact, mail-configuration opinions that aren't exploitable, scanner output with no analysis attached, and reports that a static page has no rate limiting.

What I ask

  • Don't degrade the service. No denial of service, no load testing, no automated scanning heavy enough to be indistinguishable from an attack.
  • Don't touch other people's data. If you find a way to reach it, stop there and tell me. Proving you could is enough; you don't need to.
  • No social engineering, no physical intrusion. Not against me, not against anyone I work with.
  • Give me a reasonable window before publishing. Ninety days is my default, and I'm usually ready long before that. If we disagree about the timeline, say so.

What I commit to

  • An acknowledgement within three working days, from a human.
  • An initial assessment (valid, not valid, or need more information) within ten working days.
  • Progress updates while it's open, without you having to chase me.
  • Telling you when it's fixed, and confirming you're happy the fix is real.
  • Credit by default. Your name, handle, or whatever you'd like on it. If you'd rather stay anonymous, that's equally fine. Just say.

Safe harbour

If you act in good faith and stay inside this policy, I will not pursue legal action against you, and I won't ask anyone else to. If something you did looked worse than it was, tell me what happened and I'll take you at your word.

This safe harbour covers me, and only me. It can't bind a third party whose systems you reach through mine, and it isn't legal advice.

Rewards

There's no bug bounty and no money. You get proper credit, a real conversation about the finding, and a quick answer.

Last updated 2026-08-18. Also published as security.txt.