🔐 ImpactID Responsible Disclosure Policy

1. Purpose

ImpactID is committed to protecting the confidentiality, integrity, and availability of our services and user data. We welcome reports from security researchers and will act quickly to validate, resolve, and publicly acknowledge legitimate findings.

2. Scope

In scopeOut of scope
*.impactid.nl production systemsDoS / DDoS or stress-testing
Web, API, mobile apps“Best-practice” headers only (unless exploitable)
Open-source repos under ImpactID orgClick-jacking on pages without sensitive data
3rd-party services used by usRate-limit or brute-force tests

Note: If you believe an out-of-scope issue can lead to a critical exploit, report it anyway — we will evaluate it.

3. Guidelines for Responsible Testing

4. Safe Harbor

If you follow this policy:

5. How to Report

Please report any vulnerability via:

Include:

6. Our Response Process

StageTarget Timeframe
Acknowledge report≤ 2 business days
Initial assessment≤ 5 days
Fix or mitigationDepends on severity (usually ≤ 30 days)
Public disclosureBy mutual agreement after fix

8. Legal Notice

This policy does not grant permission to act unlawfully. ImpactID reserves the right to update this policy at any time.