logo level
SME
Agency
Large enterprise
contactOperationalControl Panel

Responsible disclosure

At Level27, we place great importance on the security and integrity of our systems. We value the assistance of ethical hackers and external security researchers in identifying and reporting vulnerabilities. If you have discovered a potential security issue, we encourage you to report it to us through our Responsible Disclosure program.

image

What is Responsible Disclosure?


Responsible Disclosure is an ethical approach in which security researchers, hackers, and other involved parties notify us of security issues in our systems without misusing the information, sharing it with others, or causing harm to our systems or users.


How do you report a vulnerability?


If you have discovered a security vulnerability, we kindly ask you to report it to us as soon as possible. You can do so by sending an email to our Responsible Disclosure team at [responsibledisclosure@level27.be]. Please include all relevant details, such as a clear description of the issue, steps to reproduce it, and any proof-of-concept code or other supporting information.


What can you expect from us?


When you report a security vulnerability through our Responsible Disclosure program, you can expect the following:


* A prompt response confirming we have received your report.

* Open and transparent communication throughout the assessment, handling, and resolution of the issue.

* A reasonable timeframe to investigate and resolve the issue, depending on its complexity and any necessary collaboration with third parties.

* If applicable, a mention of your name (with your consent) in our acknowledgments list for Responsible Disclosure.


What do we expect from you?


We expect you to:


* Respect confidentiality and not share the information with others.

* Not exploit the vulnerability, cause damage, or access data that does not belong to you.

* Comply with applicable laws and regulations and avoid disrupting our systems.

* Only access systems you are authorized to and only test within the scope we have defined.


We would like to emphasize that we value responsible and ethical reporting of security issues and aim to maintain a good relationship with the security community.