Responsible disclosure

Last updated 9 March 2026 4 min read

Responsible Disclosure report

Shazzoo considers it essential that ICT systems are secure and strives for a high level of security. Nevertheless, a weakness may occur in one of these systems.

Vulnerabilities in ICT systems of Shazzoo
If you have found a weakness in one of Shazzoo's ICT systems, we would like to hear from you. That way we can take the necessary measures to fix the vulnerability as quickly as possible. To deal responsibly with vulnerabilities found in ICT systems, there are agreements. You may hold Shazzoo to these when you find a weakness in one of the systems.

Shazzoo asks you to
Email your findings to shazzoo-nl@protonmail.com.
Provide sufficient information to reproduce the problem so that Shazzoo can resolve it as quickly as possible. Usually the IP address or URL of the affected system and a description of the vulnerability are sufficient, but more complex vulnerabilities may require more.
Leave your contact details so that Shazzoo can get in touch with you to work together on a secure result. Leave at least an email address or phone number.
Report the vulnerability as soon as possible after discovering it.
Not share information about the security problem with others until it has been resolved.
Handle knowledge of the security problem responsibly by not performing any actions beyond what is necessary to demonstrate the security problem.
In any case, avoid the following actions:

  • Placing malware

  • Copying, changing or deleting data in a system (an alternative is to make a directory listing of a system).

  • Making changes to the system.

  • Repeatedly gaining access to the system or sharing access with others.

  • Using so-called "brute forcing" to gain access to systems.

  • Using denial-of-service or social engineering.


What you can expect:

If, when reporting a vulnerability you have found in an ICT system of Shazzoo, you meet the conditions above, Shazzoo will not attach any legal consequences to this report.

  • Shazzoo treats a report confidentially and does not share personal data with third parties without the reporter's permission, unless this is required by law or by a court ruling.

  • By mutual agreement, Shazzoo can, if you wish, mention your name as the discoverer of the reported vulnerability.

  • Shazzoo sends you an acknowledgement of receipt within one working day.

  • Shazzoo responds to a report within three working days with an assessment of the report and an expected date for a solution.

  • Shazzoo keeps the reporter informed of the progress in resolving the problem.

  • Shazzoo resolves the security problem you have found in a system as quickly as possible, but no later than within 60 days. By mutual agreement it can be decided whether and how the problem will be published once it has been resolved.

  • Shazzoo offers a reward as a thank-you for your help. Depending on the severity of the security problem and the quality of the report, this reward can vary from a minimum of 50 to a maximum of 1000 euros. It must concern a serious security problem not yet known to Shazzoo.

Vulnerabilities in ICT systems of third parties
Shazzoo would also like to hear from you if you have found a weakness in a government system or in a system with a vital function. For systems of other owners/administrators and/or suppliers, you should first approach the organisation itself. If the organisation does not respond, or does not respond properly, you can inform Shazzoo. Shazzoo will then act as an intermediary to reach a result together.

For reports about third-party systems

  • Shazzoo responds to a report within three working days by contacting the owner and giving you a response.

  • The owner is primarily responsible for keeping the reporter informed of the progress in resolving the problem.

  • Shazzoo will help the owner with advice so that the security problem can be resolved as quickly as possible.

  • Shazzoo asks you to let us know whether and how there has already been contact with the organisation.