Vulnerability Disclosure Policy
We take security seriously at Acendae. If you've found a vulnerability, we want to hear from you — and we commit to working with you responsibly.
Scope
This policy applies to all systems owned and operated by Acendae, including:
- acendae.com and all subdomains
- acendae.com (Dutch, site root), acendae.com/en (English), and localized marketing routes
- Any Acendae-branded web applications and APIs
Systems belonging to our clients are explicitly out of scope unless those clients have a separate engagement with Acendae's security team.
How to Report
Send your report to helpdesk@acendae.com. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce or a proof-of-concept
- The URL(s) and parameters affected
- Your name or handle (optional — anonymous reports are accepted)
What to Expect
Acknowledgement within 3 business days
We will confirm receipt of your report and let you know we're investigating.
Status update within 10 business days
We'll share our assessment of the issue and an expected resolution timeline.
Coordinated disclosure
We ask that you give us reasonable time to fix the issue before any public disclosure. We'll work with you to agree on a timeline.
Safe Harbour
Acendae will not pursue legal action against researchers who:
- Act in good faith and do not exploit or exfiltrate data beyond what is necessary to demonstrate the vulnerability
- Report findings through the channels described in this policy
- Avoid disrupting or degrading our services during testing
- Do not access, modify, or delete data belonging to our users or clients
Out of Scope
The following are not eligible for this programme:
- Social engineering or phishing attacks against Acendae staff
- Physical security issues
- Denial-of-service attacks
- Vulnerabilities in third-party services not under our control
- Issues that require unlikely user interaction or are purely theoretical
Contact
Email us at helpdesk@acendae.com. For a full machine-readable version of our contact and policy information, see our security.txt.