Security

Responsible disclosure

Do you work on software security and have you found a weak spot in an AIStudio system? Report it to us. We fix it and we tell you what we did with it.

Report tosecurity@aistudio.nl

About this translation

This is a translation of our Dutch responsible disclosure policy. In case of any difference, the Dutch text applies. You can find it at aistudio.nl/responsible-disclosure.

How to report something

Email your finding to security@aistudio.nl. Describe what you found, where you found it and which steps are needed to reproduce it. Screenshots or a short recording help. Tell us how to reach you if we have questions.

What you can expect from us

  • Within three working days a reply from a person, not an automated acknowledgement.
  • Within ten working days a substantive assessment: what we see, how serious we judge it and when we will fix it.
  • We keep you informed until it is fixed and tell you when that has happened.
  • Your report stays confidential. We do not share your details with third parties without your consent.
  • Report in good faith and stick to the rules below, and we will not press charges.

Rules of engagement

  • Do not go further than needed to demonstrate the vulnerability.
  • Do not change or delete data and do not use other people’s data.
  • No brute force, no denial of service, no spam or phishing aimed at our employees or clients.
  • No social engineering and no physical access to our buildings or those of our clients.
  • Do not share your finding with others while we are still working on it.
  • Systems belonging to our clients are out of scope. If you are unsure where something belongs, ask us first.

What we look at first

Reports about access to data, about authentication and authorisation, or about the AIStudio Assist platform are picked up with priority. Mostly theoretical findings, such as a missing header without demonstrable risk, are picked up later.

Giving something back

For a serious vulnerability we pay a financial reward. We do not work with fixed amounts: we set the amount per report, based on the impact and the risk of the finding and the quality of your report. We tell you what we decided and why.

No reward follows if the vulnerability was already known to us or already reported by someone else, or if you did not stick to the rules above.

If you would rather be named, or named as well, say so in your report. We will add you to our thank-you page as soon as it exists.

Questions

Is it not about a vulnerability?

For questions about privacy or your data, email privacy@aistudio.nl. See also our privacy statement. For anything else, just give us a call.

Get in touch