Responsible Disclosure

Modero considers the security of its systems a top priority. Despite our strong commitment to system security and the efforts we make to safeguard our systems, vulnerabilities may still exist. If you discover a vulnerability, we would like to know about it so that we can take measures to remedy it as quickly as possible. We kindly ask you to help us better protect our customers and our systems.

Please do the following:

  • Email your findings to disclosure@modero.be.
  • Do not exploit the vulnerability or issue you have discovered, for example by downloading more data than necessary to demonstrate the vulnerability, or by deleting or modifying other people’s data.
  • Do not share the problem with others until it has been resolved.
  • Do not carry out attacks on physical security, through social engineering, distributed denial of service, spam, or third-party applications.
  • Provide sufficient information to reproduce the problem so that we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability are sufficient, but for complex vulnerabilities more explanation may be required.

What we promise:

  • We will respond to your report within 5 working days with our evaluation and an expected resolution date.
  • If you have followed the instructions above, we will not take legal action against you regarding the report and will confirm this in writing by email.
  • We will treat your report strictly confidentially and will not share your personal data with third parties without your consent.
  • We will keep you informed of the progress in resolving the issue.
  • In public information about the reported problem, we will mention your name as the discoverer of the issue (unless you prefer otherwise).

We strive to resolve all problems as quickly as possible and would like to play an active role in the eventual publication about the issue once it has been resolved.