Our Commitment
Cyvra is a cybersecurity company and we hold ourselves to a high standard when it comes to the security of our own systems and website. We welcome reports from security researchers and members of the public who discover vulnerabilities that affect us.
If you act in good faith and follow this policy, we will not pursue legal action against you, we will acknowledge your report, and we will work to resolve the issue promptly.
Scope
This policy applies to security vulnerabilities found in:
- Our website at cyvra.nl and its subdomains
- Any other digital systems or services operated by Cyvra
Please do not test the systems of our clients or partners — those are out of scope and such testing may have legal consequences.
How to Report
Send your report to [email protected] with the subject line Security Vulnerability Report. Please include:
- A description of the vulnerability and its potential impact
- Steps to reproduce the issue (proof of concept if available)
- Any affected URLs, parameters, or system components
- Your contact details so we can follow up
What to Expect
- Acknowledgement — we will confirm receipt of your report within 3 business days
- Assessment — we will assess the severity and scope within 10 business days
- Resolution — we aim to resolve critical issues within 30 days and will keep you informed of progress
- Credit — with your permission, we are happy to acknowledge your contribution publicly
Guidelines
To act within this policy, please:
- Avoid accessing, modifying, or deleting data that does not belong to you
- Avoid actions that could disrupt or degrade our services
- Do not share details of the vulnerability publicly before we have had the opportunity to fix it
- Do not use automated scanning tools against our infrastructure without prior agreement
Out of Scope
- Denial of service attacks
- Social engineering or phishing of Cyvra staff
- Physical security issues
- Reports from automated scanners without accompanying analysis
- Issues in third-party services we use but do not control
Found a vulnerability? Please let us know.
Report a Vulnerability