Skip to content
All systems nominalMITRE ATT&CK · PTES · TIBER-EU · TLPT · DORA
//  —  Legal

Vulnerability disclosure policy

How to report a security issue in RagnarOps Security Labs' own website or systems, what to expect from us, and the safe harbour that covers good-faith research.

Last updated

This policy covers vulnerabilities in systems we operate ourselves — this website and any tooling or infrastructure we publish. It does not cover client engagements: those are scoped and authorised separately, under a signed agreement.

How to report

Email contact@ragnaropsec.com with:

  • What you found and where (URL, endpoint, or component)
  • Steps to reproduce it
  • What you were able to demonstrate — stop at proof of access, and avoid retrieving or retaining more than that requires
  • Your assessment of impact, if you have one
  • How you would like to be credited, if at all

Safe harbour

Good-faith research against our own systems, conducted within the boundaries below, will not lead to legal action from us.

This is our own commitment. It does not bind the Dutch public prosecutor (Openbaar Ministerie) or any other authority, who could independently decide whether Dutch computer-crime law applies. We are not aware of a case where good-faith research reported under a policy like this one led to prosecution, and the Dutch National Cyber Security Centre's coordinated-disclosure guidance reflects the same practice — but we can only promise what we control.

  • Stop at proof of access — do not access, exfiltrate, modify, or retain data beyond what demonstrating the issue requires.
  • No denial-of-service testing or anything that degrades the service for other users.
  • No social engineering of our staff, contractors, or suppliers, and no physical attempts against our premises or theirs.
  • No testing of the third-party services we use for email delivery, database hosting, or site hosting — report a problem with the boundary between our systems and theirs, not an attack on the provider itself.
  • Give us a reasonable window to fix the issue before you publish or disclose it publicly, and coordinate the disclosure date with us.

Step outside these boundaries and this safe harbour no longer applies.

Out of scope

  • Social engineering of any kind
  • Physical attacks against our premises or hardware
  • Denial-of-service or load testing
  • Vulnerabilities in third-party services we use, rather than in our own systems or how we integrate with them
  • Reports generated purely by automated scanners without a demonstrated, reproducible issue

No bug bounty

We do not run a bug bounty program and do not pay for reports. We will acknowledge good-faith reports and credit you if you want that, but there is no financial reward on offer.

What to expect from us

We aim to acknowledge a report within 5 business days. That is a target, not a guaranteed response time — we are a small team and cannot commit to a service level here. Once we have triaged the report, we will tell you what we intend to do and roughly when.

Coordinated disclosure

If you plan to publish, coordinate the date with us first. We will not sit on a valid report indefinitely — if we go quiet, that is a failure on our part, not a reason to assume the issue is not real.