Reporting a vulnerability

Found a security issue in BonDepot? Let us know. We take reports seriously and appreciate the effort — even if it turns out to be minor.

How to report

Send an email to security@bondepot.eu with "vulnerability" in the subject line. Describe as precisely as you can what you found and how we can reproduce it — a URL, the steps, and what you expected versus what happened. Screenshots or a short log excerpt help. English or Dutch, both are fine.

These details are also listed in /.well-known/security.txt.

What you can expect from us

A reply from a human

Within five working days we confirm your report and tell you what we are doing with it. Not an automated acknowledgement that goes nowhere.

We keep you posted

You will hear from us whether we can confirm the issue, and when it has been fixed. If a fix takes longer, we tell you why.

No legal action

As long as you stay within the rules below, we will not take legal action against you over your report — not even if something went wrong while you were investigating.

Credited by name, if you want

We are happy to credit you as the finder once the issue is fixed. Staying anonymous is fine too. We do not run a bug bounty: there is no money involved, and we would rather say so up front than afterwards.

What we ask of you

This is about the books of real businesses. Treat them as carefully as you would want someone to treat yours.

What is in scope

Reports about https://www.bondepot.eu and the application at app.bondepot.eu are welcome. Third-party services we use (our hosting provider or payment provider, for instance) fall outside this policy — report those to the party in question. Findings without a demonstrable security risk, such as a missing header that no vulnerability follows from, or the output of an automated scan without a working proof of concept, we take on board as an improvement but do not handle as a report.

Would you rather first read how we handle data?

Where your books live, who can get to them, and what we do not do.