Security policy and Coordinated Vulnerability Disclosure
Have you found a technical vulnerability in our website or systems? Report it responsibly in line with this policy, so that we can resolve the problem before others misuse it.
This policy applies to publicly accessible websites, domains and systems that are demonstrably managed by Finass Advies B.V., including www.finassverzekert.nl.
Services, modules and websites of insurers, banks, comparison platforms, hosting parties and other external suppliers fall outside our management. In principle, report a vulnerability in an external system directly to its owner or supplier.
2 Reporting a vulnerability
Send your report to info@finassverzekert.nl with Security report as the subject.
Preferably state:
the URL, domain, IP address or system to which the report relates;
a clear description of the vulnerability and the possible impact;
the steps that allow us to reproduce the finding;
any screenshots or limited technical evidence;
your contact details, so that we can ask additional questions.
Do not include personal data, customer data, passwords or complete data files if this is not strictly necessary. If the report is highly sensitive, contact us first to agree on a suitable way of exchanging it securely.
3 What we ask of you
Act carefully and only in so far as this is needed to demonstrate the vulnerability.
Do not misuse the vulnerability.
Do not view, copy, change or delete more data than is strictly necessary as evidence.
Stop your research as soon as you have sufficiently demonstrated that the vulnerability exists.
Do not place malware and do not obtain lasting access to systems.
Do not use social engineering, phishing, physical attacks or attacks on staff.
Do not carry out denial-of-service attacks and do not use automated scans that place an excessive load on systems.
Do not make changes that affect the availability, integrity or operation of systems.
Do not share the vulnerability with third parties and do not make it public before we have had sufficient time to investigate and resolve the problem.
4 What you can expect from us
We aim to confirm your report within five working days.
We assess the report and inform you, where possible, within ten working days about the initial outcome and the expected next steps.
The time needed for a fix depends on the nature, severity and complexity of the vulnerability and on any dependency on suppliers. We keep you informed where reasonably possible.
If you act in good faith and comply with this policy, we will in principle not take legal action against you because of the research carried out. This undertaking does not apply in the event of deliberate misuse, damage, extortion, disclosure without prior agreement or other unlawful acts.
5 Disclosure
Agree any disclosure with us in advance. As a starting point, we ask you not to make details public while the vulnerability has not been remedied and in any event not within 90 days of our acknowledgement of receipt, unless we agree a different period in writing.
We may ask you to postpone disclosure when a fix depends on an external supplier or when disclosure creates a concrete risk for customers or systems.
6 Reward and recognition
Finass Advies B.V. has no public reward or bug bounty programme. A report therefore does not automatically give rise to a right to a financial payment or other reward.
With your consent only, we may state your name in recognition of a carefully reported and relevant vulnerability.
7 Not a reporting point for general questions
This reporting point is intended solely for technical security vulnerabilities. Questions about insurance, claims, privacy, invoices, spam or general services can be sent to info@finassverzekert.nl.
Do you suspect a data breach involving personal data? Report it with the same urgency via info@finassverzekert.nl or by telephone on 072 - 509 24 56, so that we can meet the statutory reporting deadline.
8 Changes
We may adjust this policy when our systems, procedures or statutory obligations change. The date at the top of this page indicates when the policy was last updated.