Security Policy

I take the security of this site seriously. If you believe you have found a security vulnerability in nefkens-ict.nl, I welcome your report and thank you in advance for disclosing it responsibly.

Scope

In scope

  • nefkens-ict.nl and www.nefkens-ict.nl (this website and its content)

Out of scope

  • Third-party services embedded in or linked from the site (e.g. Google Tag Manager, Credly, LinkedIn) — please report those to the respective vendor.
  • The hosting platform’s shared infrastructure (STRATO). Report platform-level issues to STRATO directly.
  • Findings that require physical access, social engineering, or access to a user’s device or account.

How to report

Please email security@nefkens-ict.nl with:

  • A clear description of the issue and its potential impact.
  • The steps required to reproduce it (URLs, requests, payloads, screenshots).
  • Any relevant version, configuration, or environment details.

If you need to share sensitive details, ask and I will provide a means of encrypted communication.

Guidelines for researchers

When investigating, please:

  • Act in good faith and avoid privacy violations, data destruction, and any disruption of the service.
  • Use only your own accounts and test data — do not access, modify, or exfiltrate data that is not yours.
  • Do not run automated scanning that degrades availability, and avoid denial-of-service, spam, or social-engineering techniques.
  • Give me a reasonable opportunity to remediate before any public disclosure.

Acting in line with these guidelines, I will not pursue or support legal action related to your research.

What to expect

  • Acknowledgement: within 5 business days of your report.
  • Assessment & updates: I will validate the issue and keep you informed of progress.
  • Resolution: valid issues will be remediated as quickly as is practical, prioritised by severity.
  • Recognition: with your permission, I am happy to credit your contribution.

This is a personal site run by a single maintainer, so please allow reasonable time for a response. There is no paid bug-bounty program.

Safe harbour

Research conducted in accordance with this policy is considered authorised. If legal action is initiated by a third party against you for activity that complied with this policy, I will make it known that your actions were authorised.


Machine-readable contact information is published at /.well-known/security.txt per RFC 9116.

Last updated: 27 July 2026.