---
title: "Responsible Disclosure Policy"
description: "WebinarGeek is committed to working openly with the security community to mitigate and resolve vulnerabilities responsibly. We look forward to your submissions and thank you for your efforts to help us keep our systems secure."
publishedAt: "2024-04-16T07:47:52.428Z"
modifiedAt: "2026-07-23T11:50:26.064Z"
author: "WebinarGeek"
tags:
[]
canonicalUrl: "https://www.webinargeek.com/nl/responsible-disclosure-policy"
language: "nl"
---

# Responsible Disclosure Policy

# Responsible Disclosure Policy

At WebinarGeek, we recognize the critical role security plays in providing quality services to our global user base. Despite our continuous efforts to safeguard our systems, which you can find outlined [here](https://www.webinargeek.com/security-and-availability), vulnerabilities can emerge. We believe in working collaboratively with the security research community to identify and resolve issues quickly and efficiently. We encourage researchers and ethical hackers to engage with us responsibly to improve our digital environment.

**Guidelines for Reporting Vulnerabilities**

We invite security researchers and enthusiasts to report potential vulnerabilities identified in our systems with the understanding and agreement to the following guidelines:

- **Contact:** Direct your findings to [security@webinargeek.com](mailto:security@webinargeek.com). Please provide detailed information, including steps to reproduce the vulnerability, so our security team can validate and address the issue promptly. We are confident that regular mail encryption is sufficient enough to provide the confidentiality needed to report a vulnerability. However, if you feel that your vulnerability report requires the use of PGP encryption, you can find our public key at the bottom of this page.
- **Acknowledgment:** We commit to acknowledging receipt of your report within two working days.
- **Investigation & Resolution:** Our dedicated team will investigate reported vulnerabilities and aim to resolve them within one week of acknowledgment. The complexity and severity of the issue may affect resolution times.
- **Confidentiality:** We ask that you maintain the confidentiality of any vulnerabilities discovered until we have resolved them. We will coordinate with you on the public disclosure of any findings.
- **Rewards & Acknowledgment:** While not all reports may qualify for a reward, we assess submissions on a case-by-case basis for potential acknowledgment or reward. The nature of the reward will depend on the severity and impact of the discovered vulnerability.
- **Legal Protection:** We promise not to initiate legal action against individuals who report vulnerabilities following these guidelines, provided that they have not engaged in unlawful activities or misuse of the discovered vulnerability.

**What We Do Not Accept**

- Attempts to access, download, or modify data belonging to others.
- Denial of service (DoS) attacks.
- Spamming.
- Social engineering or physical attacks against our property or data.

**Rewards Program**

- Rewards are determined based on the risk level of the reported security vulnerability and are at the discretion of WebinarGeek.
- In the event of duplicate reports, the reward will be issued to the first reporter.
- Rewards are subject to change and may vary according to the uniqueness and severity of the vulnerability.
- Rewards can only be paid out using PayPal outside Europe. Within Europe (IBAN) we also support bank transfers.

**Out of Scope**

- Reports of non-security issues or inquiries.
- Third-party services and software not directly managed by WebinarGeek.
- Publicly known vulnerabilities that have already been addressed.
- Vulnerabilities which are:
  
  - HTTP 404 codes or other non HTTP 200 codes
    - Version banners on public services
    - Clickjacking on pages without a login
    - Cross-site request forgery (CSRF) on forms that can be accessed anonymously
    - Lack of 'secure' / 'HTTP Only' flags on non-sensitive cookies
    - Notifications related to SSL certificate (e.g. weak cipher)
    - Using the HTTP OPTIONS Method
    - Host Header Injection
    - Lack of SPF, DKIM and DMARC records
    - Lack of DNSSEC
    - The lack of HTTP Security Headers
    - Reporting outdated versions of software without a proof of concept or working exploit
    - Business logic flaws, including abuse of intended product flows, pricing or billing logic, permission models by design, or issues that require unrealistic user behavior, unless they demonstrate a clear security vulnerability with direct impact
    - Best practices

**Closing Statement**

Your contributions are invaluable to the security and integrity of our services. WebinarGeek is committed to working openly with the security community to mitigate and resolve vulnerabilities responsibly. We look forward to your submissions and thank you for your efforts to help us keep our systems secure.

For any further questions or submissions, please reach out to [security@webinargeek.com](mailto:security@webinargeek.com).

**Public PGP key**
