Legal
Legal
Responsible disclosure
Last updated: 26 May 2026
If you find a security issue in our systems, tell us. This page says how to report it and how we reply.
Report a vulnerability
If you find a vulnerability in one of our systems, contact us. Follow the conditions below so we can fix it.
Conditions
Follow these conditions:
- Email your findings to hello@aquadome.ai. We will contact you so we can exchange those details safely. The IP address, domain name, or URL of the affected system, plus a description of the vulnerability, is usually enough. A more complex issue may need more.
- Do not abuse the problem, and do not share it with others until it is fixed.
- Delete any confidential data you obtained right away, and no later than when the leak is fixed.
- Do not attack physical security, use social engineering, run a distributed denial of service, send spam, or attack third-party applications.
If you follow these conditions, we will not take legal action against you for the report.
Scope
This policy covers only:
- www.aquadome.ai, the public marketing site
- app.aquadome.ai, the Aquadome application
- Infrastructure and services that Aquadome BV runs to support those sites
Process
We handle a report as follows:
- We reply as soon as we can, and within four working days at the latest. When we can, we include our assessment and a date for a fix. We will tell you how the work is going.
- We try to fix every problem quickly. If you publish about the problem, we want to be involved after the fix.
- We keep your report confidential. We do not share your personal information with third parties without your permission, unless the law requires it.
No invitation for abuse
When you test a vulnerability, keep the test proportional. You do not need to prove that a large (D)DoS attack would take one of our services offline. We already know that.
This is not an invitation to scan our networks for weak spots. Brute-force attacks, (D)DoS, and social engineering are outside this policy.
Do not perform (D)DoS attacks.
Do not test rate limits on forms. The disruption is worse than anything you might learn about a rate limit.
Exclusions
We exclude reports based on these findings:
- SPF, DKIM, or DMARC records, or missing DNSSEC.
- Missing HTTP security headers.
- CSRF on forms that anyone can open without a session.
- Brute-force, (D)DoS, and rate-limit findings.
- Clickjacking and related vulnerabilities.
- Unsafe SSL/TLS protocols and related misconfigurations.
- Server or application versions from outside vendors that look outdated, unless you prove the vulnerability and prove you exploited it.
- Version exposure, unless you include a proof of concept of a working exploit.
- Known public files or directories, or information that is not sensitive.
- Reports from automated tools and scans.
Do not send these reports. Treat them as known risks we accept, or as issues already reported.
Reward
We may offer a reward for a security issue we did not already know about, if the report meets this policy. The size of the reward depends on the severity of the issue and the quality of the report.
A report does not qualify if we already knew about the issue, or if the risk is low or accepted.
We do not pay people who live in a country on an EU or UN sanctions list.
Attribution
This policy is based on responsibledisclosure.nl and the NCSC Coordinated Vulnerability Disclosure guideline. For the rest of our security practices, see Security.
