Inleiding
Emmaüs neemt de beveiliging van onze systemen en de bescherming van gevoelige informatie zeer ernstig. Ondanks onze inspanningen kunnen er toch kwetsbaarheden bestaan. Daarom verwelkomen wij feedback van beveiligingsonderzoekers, ethische hackers en de bredere gemeenschap via ons Vulnerability Disclosure Programma (VDP). Als je een mogelijke beveiligingsprobleem ontdekt in één van onze systemen, applicaties of diensten, moedigen we je aan om dit op een verantwoorde manier te melden.
Door samen te werken, kunnen wij, onze patiënten, medewerkers en partners beter beschermen. Jouw kwetsbaarheidsmelding helpt ons onze beveiliging verder te versterken. Wij waarderen je inzet en samenwerking om de systemen van Emmaüs veilig te houden.
Emmaüs en zijn voorzieningen werkt voor de coördinatie van het VDP samen met Intigrity. Dit stelt ons in staat om meldingen van kwetsbaarheden op een gestructureerde, veilige en efficiënte manier te ontvangen en op te volgen.
In scope
Dit VDP programma is van toepassing op de systemen, diensten en endpoints van Emmaüs die zijn opgenomen in onze gepubliceerde lijst van assets. Zoals bijvoorbeeld:
- Publiek beschikbare websites
- Publiek beschikbare webapps
We bieden geen financiële of materiële beloningen voor gemelde kwetsbaarheden. Wel hechten we veel waarde aan de bijdragen van securityonderzoekers en waarderen we hun inspanningen om onze beveiliging te verbeteren.
Out of scope
Systemen die niet voorkomen in de gepubliceerde lijst van assets, vallen buiten het toepassingsgebied van het VDP programma.
Een aantal kwetsbaarheden en/of testmethoden zoals bijvoorbeeld Banner grabbing, e-mail bombing of social engineering zijn niet toegestaan en vallen buiten het toepassingsgebied. Een volledige lijst is beschikbaar via het Intigrity platform.
Hoe een kwetsbaarheid rapporteren
Om een kwetsbaarheid te rapporteren, vragen wij je om je eerst te registreren op het Intigrity-platform. Na registratie krijg je toegang tot ons volledige programma, inclusief de scope, richtlijnen en voorwaarden. Meldingen die via het platform worden ingediend, worden opgevolgd door ons securityteam.
We vragen om geen kwetsbaarheden via andere kanalen (zoals e-mail of sociale media) te delen, zodat we een consistente en beveiligde afhandeling kunnen garanderen.
Meer informatie nodig
Meer detailinformatie over het VDP programma van Emmaüs en de bijhorende voorzieningen is beschikbaar via het Intigrity platform.
Introduction
Emmaüs takes the security of its systems and the protection of sensitive information very seriously. Despite our efforts, vulnerabilities may still exist. That is why we welcome feedback from security researchers, ethical hackers, and the wider community through our Vulnerability Disclosure Program (VDP). If you discover a potential security issue in one of our systems, applications, or services, we encourage you to report it responsibly.
By working together, we can better protect our patients, employees, and partners. Your responsible disclosure helps us further strengthen our security. We appreciate your efforts and collaboration in keeping Emmaüs systems secure.
Emmaüs and its affiliated entities collaborate with Intigrity for the coordination of the VDP. This enables us to receive and handle vulnerability reports in a structured, secure, and efficient manner.
In scope
This VDP applies to the Emmaüs systems, services, and endpoints included in our published list of assets.These may include, for example:
- Publicly accessible websites
- Publicly accessible web applications
We do not offer financial or material rewards for reported vulnerabilities. However, we highly value the contributions of security researchers and appreciate their efforts in helping us improve our security.
Out of scope
Systems that are not listed in the published asset list are considered out of scope for this VDP.
Certain vulnerabilities and/or testing methods, such as banner grabbing, email bombing, or social engineering, are not allowed and fall outside the scope of this program. A full list is available via the Intigrity platform.
How to Report a Vulnerability
To report a vulnerability, we ask that you first register on the Intigrity platform. After registration, you will gain access to our full program, including scope, guidelines, and terms. Reports submitted via the platform will be handled by our security team.
We kindly ask you not to share vulnerabilities through other channels (such as email or social media), in order to ensure a consistent and secure handling process.
Need more information?
More detailed information about the Emmaüs VDP and its affiliated entities is available via the Intigrity platform.