Responsible Disclosure.

We take the security of our systems seriously. Found a vulnerability? Let us know.

Last updated: 16 March 2026

Scope

This policy applies to the following domains and systems:

  • easeo.nl
  • aldewereldconsultancy.nl
  • cloud.aldewereldconsultancy.nl
  • easeohost.nl

Vulnerabilities in systems not on the list above fall outside the scope of this policy.

What we expect from you

If you discover a security issue, we ask you to do the following:

  • Report the vulnerability as soon as possible via security@easeo.nl.
  • Describe the problem clearly and with enough detail for us to reproduce it.
  • Do not exploit the vulnerability. Do not take any action beyond what is needed to demonstrate the issue.
  • Do not install backdoors, modify data or delete data.
  • Do not exfiltrate data. If you accidentally gain access to personal data or confidential information, stop immediately and report it.
  • Do not carry out attacks that affect the availability of our services (denial of service, brute force, social engineering, spam).
  • Do not share the vulnerability with third parties until it has been resolved and we have given permission to publish.
  • Give us a reasonable period to fix the problem before you publish. Our guideline is 90 days after your report.

What we promise

  • We confirm receipt of your report within 5 working days.
  • We keep you informed of the progress in resolving the vulnerability.
  • We fix security issues as quickly as possible, depending on complexity and severity.
  • We will not take legal action against you if you act in accordance with this policy.
  • We treat your report confidentially and do not share your personal data with third parties without your consent, unless legally required to do so.
  • We're happy to credit you as the discoverer of the vulnerability (unless you wish to remain anonymous).

No bug bounty

EASEO currently offers no financial reward for reporting vulnerabilities. We appreciate your effort and offer recognition to researchers who report responsibly.

Out of scope

The following findings generally fall outside the scope of this policy:

  • Findings from automated scans without manual verification.
  • Missing HTTP headers that pose no direct security risk.
  • SPF/DKIM/DMARC configuration issues without demonstrated impact.
  • Clickjacking on pages without sensitive actions.
  • Rate limiting on non-authentication endpoints.
  • Vulnerabilities in third-party software for which a patch is already available.

Contact

Report security issues exclusively via security@easeo.nl. In your email, please include:

  • A description of the vulnerability.
  • Steps to reproduce the problem.
  • Any screenshots or proof-of-concept code.
  • The affected domain or system.

Encrypt your email if possible. Contact us for our PGP key.

EASEO (Aldewereld Consultancy)

Nieuwe Hemweg 26, 1013 CX Amsterdam (postal address only — visits by appointment)

Security reports: security@easeo.nl

General: info@easeo.nl

Chamber of Commerce (KvK): 61862533