Found a security issue in BonDepot? Let us know. We take reports seriously and appreciate the effort — even if it turns out to be minor.
Send an email to security@bondepot.eu with "vulnerability" in the subject line. Describe as precisely as you can what you found and how we can reproduce it — a URL, the steps, and what you expected versus what happened. Screenshots or a short log excerpt help. English or Dutch, both are fine.
These details are also listed in /.well-known/security.txt.
Within five working days we confirm your report and tell you what we are doing with it. Not an automated acknowledgement that goes nowhere.
You will hear from us whether we can confirm the issue, and when it has been fixed. If a fix takes longer, we tell you why.
As long as you stay within the rules below, we will not take legal action against you over your report — not even if something went wrong while you were investigating.
We are happy to credit you as the finder once the issue is fixed. Staying anonymous is fine too. We do not run a bug bounty: there is no money involved, and we would rather say so up front than afterwards.
This is about the books of real businesses. Treat them as carefully as you would want someone to treat yours.
Reports about https://www.bondepot.eu and the application at app.bondepot.eu are welcome. Third-party services we use (our hosting provider or payment provider, for instance) fall outside this policy — report those to the party in question. Findings without a demonstrable security risk, such as a missing header that no vulnerability follows from, or the output of an automated scan without a working proof of concept, we take on board as an improvement but do not handle as a report.
Where your books live, who can get to them, and what we do not do.