Security Policy
I take the security of this site seriously. If you believe you have found a security vulnerability in nefkens-ict.nl, I welcome your report and thank you in advance for disclosing it responsibly.
Scope
In scope
nefkens-ict.nlandwww.nefkens-ict.nl(this website and its content)
Out of scope
- Third-party services embedded in or linked from the site (e.g. Google Tag Manager, Credly, LinkedIn) — please report those to the respective vendor.
- The hosting platform’s shared infrastructure (STRATO). Report platform-level issues to STRATO directly.
- Findings that require physical access, social engineering, or access to a user’s device or account.
How to report
Please email security@nefkens-ict.nl with:
- A clear description of the issue and its potential impact.
- The steps required to reproduce it (URLs, requests, payloads, screenshots).
- Any relevant version, configuration, or environment details.
If you need to share sensitive details, ask and I will provide a means of encrypted communication.
Guidelines for researchers
When investigating, please:
- Act in good faith and avoid privacy violations, data destruction, and any disruption of the service.
- Use only your own accounts and test data — do not access, modify, or exfiltrate data that is not yours.
- Do not run automated scanning that degrades availability, and avoid denial-of-service, spam, or social-engineering techniques.
- Give me a reasonable opportunity to remediate before any public disclosure.
Acting in line with these guidelines, I will not pursue or support legal action related to your research.
What to expect
- Acknowledgement: within 5 business days of your report.
- Assessment & updates: I will validate the issue and keep you informed of progress.
- Resolution: valid issues will be remediated as quickly as is practical, prioritised by severity.
- Recognition: with your permission, I am happy to credit your contribution.
This is a personal site run by a single maintainer, so please allow reasonable time for a response. There is no paid bug-bounty program.
Safe harbour
Research conducted in accordance with this policy is considered authorised. If legal action is initiated by a third party against you for activity that complied with this policy, I will make it known that your actions were authorised.
Machine-readable contact information is published at
/.well-known/security.txt per
RFC 9116.
Last updated: 27 July 2026.