Responsible disclosure policy

It is important that our software is secure. If you find a weak spot in our software, we would like to hear about it. We will then take the necessary measures as quickly as possible to remedy the vulnerability found. Treams' sub-processors are essential for a stable platform, information security and innovation. On this page you will always find the latest information.

In order to be able to deal with discovered vulnerabilities in a responsible manner, we follow a number of guidelines in doing so. You may hold us to these when you come across a weak spot in one of our software products.

If you have found a (possible) weak spot, please report it via security@treams.nl. We would appreciate it if you included your email address and telephone number, as we would like to thank you personally for your help.

In doing so, you should bear in mind the following matters:
- Make a report as soon as possible after discovering the vulnerability.
- Do not share the information about the security problem with third parties. We are very quick with patches.
- Try not to let your actions go further than is necessary to demonstrate the security problem.

It is therefore not permitted for you to:
- place malware.
- make copies of data, modify it or delete it.
- make changes in or to our systems.
- repeatedly gain access to the system or share the access with others.
- make use of so-called "brute forcing" of access to systems.
- make use of denial-of-service or social engineering.

You may expect from us:
- that, if you take the above into account, we will not attach any legal consequences to this report.
- that we treat your details confidentially.
- that, after a report has been made, we will let you know quickly how we are handling it and when you can expect a solution.
- that we will let you know when the report has been dealt with.
- that we will resolve the report as quickly as possible, taking into account the impact of the report made.
- that we thank you — in an appropriate manner — for your help.

Thank you for your help in keeping our systems secure.