1

Responsible disclosure policy

Coordinated Disclosure of Vulnerabilities

1. Purpose
Alphatronics places great importance on the security of its systems, products, services, and data. Despite the security measures in place, vulnerabilities may still exist.

With this policy, Alphatronics encourages security researchers to responsibly report potential vulnerabilities so that appropriate corrective measures can be taken.

2. Scope
This policy applies to information systems, digital products, and digital services owned by Alphatronics nv.

This policy does not apply to third-party information systems, applications, or services, even if they contain data that supports Alphatronics’ services.

3. Responsibilities
The participant shall act in good faith, comply with this policy, and report vulnerabilities as soon as possible in a confidential and responsible manner. The participant shall limit their activities to what is necessary and proportionate to identify the vulnerability.

Alphatronics treats reports confidentially, investigates them within a reasonable timeframe, and makes every effort to resolve the vulnerability.

If the participant receives assistance from a third party, that third party must comply with the same terms of this policy.

4. Reporting a Vulnerability
If a vulnerability is identified, we ask the participant to:

Report the vulnerability as soon as possible via the contact form on the website https://www.alphatronics.be/contact;
Provide a clear description of the impact and the affected systems;
Provide sufficient information to reproduce and investigate the problem;
Provide contact information so that additional information can be exchanged;
Act in accordance with the provisions of this policy.

5. Confidentiality
Under no circumstances may the participant share or disclose to third parties any information collected in connection with the vulnerability or the affected systems without our prior and express consent.

Nor is it permitted to share or disclose non-public information, including personal data, to third parties.

If the vulnerability could also affect other organizations, the participant may report this to the Belgian Cybersecurity Center (CCB). Alphatronics will itself comply with the legal obligations regarding reporting.

6. Prohibited Actions
The following actions are not permitted by the researcher:

Copying, modifying, or deleting data from the system;
Installing malware;
Performing actions that affect the availability of the system, such as denial-of-service attacks;
Carrying out phishing attacks or any other form of social engineering;
Stealing passwords or carrying out brute-force attacks;
Automatically executing more than one request or command per five seconds;
Intentionally intercepting, storing, or accessing confidential information not intended for the researcher;
Using, retaining, or disseminating discovered vulnerabilities and non-public information about the system.


7. Handling of Reports
Alphatronics will:

Acknowledge receipt of the report within a reasonable timeframe;
Investigate the report and assess the risk;
Request additional information if necessary;
Make reasonable efforts to remediate the vulnerability;
Inform the reporter of the progress and completion of the investigation, to the extent that this is possible and appropriate;
Comply with its own legal obligations regarding the management and reporting of vulnerabilities.
Alphatronics reserves the right not to pursue a report further, for example, if it is of low quality or poses only a limited risk.

8. Protection of Researchers
Reporting a vulnerability does not entitle the reporter to financial compensation or other forms of compensation.

Provided the researcher acts in good faith and complies with the provisions of this policy, Alphatronics will not take any legal action regarding the vulnerability report.

9. Coordinated Disclosure
Alphatronics may, after implementing corrective measures, decide to disclose information about the vulnerability in the interest of transparency and the continuous improvement of its security.

If the participant agrees, Alphatronics may mention the participant’s name or pseudonym as acknowledgment of the report.