If you find something, tell us.
Crunchr investigates all reported vulnerabilities. Despite the effort we put into security every day, vulnerabilities can still occur — this page explains how to report one, and what to expect from us in return.
REPORTING A VULNERABILITY
Found a security or privacy vulnerability in a Crunchr service? Please report it — we welcome reports from customers, security researchers, and developers alike. This is known as responsible disclosure or Coordinated Vulnerability Disclosure (CVD).
Email vulnerability-disclosure@crunchr.com with:
- Service — which service you believe is affected.
- Observation — what happened, and what you expected instead.
- Description — as much detail as possible: steps to reproduce, screenshots, video, or supporting material (e.g. proof-of-concept code) to help us understand the issue’s nature and severity.
- Contact details — your email or phone number, in case we have questions (we prefer email). A proposed solution is welcome but not required.
We accept reports in English or Dutch.
IN SCOPE
In principle, any Crunchr-owned service is in scope, including all content on *.crunchr.com and *.crunchrapps.com.
Qualifying vulnerabilities include:
- Remote Code Execution
- Cross-Site Scripting (XSS)
- Cross-Site Request Forgery (CSRF)
- SQL Injection
- Encryption vulnerabilities
- Authentication bypasses and unauthorized data access
OUT OF SCOPE
We don’t process or reward reports that can’t be abused, or that are trivial — including output from public vulnerability scanners. Known, accepted exceptions include:
- HTTP 404s or other non-200 pages, and content spoofing/text injection on them
- Version/fingerprint banners on common public services
- Disclosure of known public files, directories, or other non-sensitive information (e.g. robots.txt)
- Clickjacking, or issues only exploitable through it
- Missing Secure/HTTPOnly flags on non-sensitive cookies
- OPTIONS HTTP method enabled
- Missing HTTP security headers (e.g. Strict-Transport-Security, X-Frame-Options, X-XSS-Protection, X-Content-Type-Options, Content-Security-Policy)
- SSL configuration issues (e.g. forward secrecy disabled, weak cipher suites)
- SPF, DKIM, or DMARC issues
- Host header injection
- Outdated software versions reported without proof of concept
- Metadata information leakage
- Missing DNSSEC
- Username/email enumeration via brute-force attempts (e.g. login or password-reset error messages)
This list of exclusions is derived from the CERT of SURF’s published exclusions (surf.nl/en/responsible-disclosure).
WE ASK YOU TO
- Report the vulnerability as soon as possible after discovering it
- Handle knowledge of the vulnerability responsibly
- Take extra care with personal and confidential data
WE ASK YOU NEVER TO
- Copy or download data, beyond what’s needed to prove your finding
- Change or delete data or services
- Access the service repeatedly, or share access with others
- Cause damage or unavailability to our services
- Share the vulnerability with others before it’s resolved
- Perform brute-force, denial-of-service, spam, or social-engineering attacks
- Physically target Crunchr personnel, offices, or data centres
- Introduce malware or backdoors
WHAT WE PROMISE
- Timely response — We’ll review your report and respond within five (5) business days with our evaluation and an expected resolution date, keeping you informed throughout. We aim to resolve confirmed vulnerabilities within sixty (60) days, and will consult you on whether and how to publish details afterward.
- Confidentiality — We handle reports in strict confidence. We won’t share your personal details with third parties without your permission, unless legally compelled to. We’ll only name you as the discoverer if you explicitly ask us to.
- No legal action — If you follow this policy, we won’t take legal action against you. The Public Prosecutor retains the right to decide independently whether to prosecute.
- Reward — We may reward valid, well-documented reports, at our discretion — the form and eligibility depend on severity, research quality, and report clarity. Only the first reporter of a given issue is eligible, and reports that don’t follow this policy are not rewarded.