Spring naar hoofdinhoud

Report a vulnerability

We take security reports seriously and appreciate you taking the time to file one.

Pick whatever works best for you

You don't have to identify yourself. Anonymous reporting is possible through the form, and you can also report indirectly via the Centre for Cybersecurity Belgium (CCB), which acts as coordinator for coordinated vulnerability disclosure. Centre for Cybersecurity Belgium (CCB)

Please don't report via a public issue or on social media, and don't publish before we've been in touch. That gives users a chance to update first.

What to include

If you can, please include:

  • Which component it concerns (see Scope below) and which version
  • How to reproduce the vulnerability
  • What an attacker could achieve with it

What you can expect from us

Acknowledgement
within 2 business days
Initial assessment
within 5 business days
Status update
at least every 2 weeks while the report is open
Publication
only once a fix is available and users have had a chance to apply it

These are commitments, not targets.

We're happy to credit responsible reporters when we publish the fix, unless you'd rather stay anonymous. We don't run a bug bounty program, so we offer recognition but no reward.

Scope

This reporting channel covers Wassalon-kassa as we deliver it, which is more than just the till:

  • Till software on the Raspberry Pi
  • Kiosk app on the customer tablet
  • Cloud layer (database, functions, realtime)
  • Owner app my.wassalonkassa.be
  • Fleet app fleet.wassalonkassa.be
  • This marketing website (wassalonkassa.be)

Vulnerabilities in third-party software we ship also belong here. We report those onward to whoever maintains the component, and fix our side of it.

Third-party services we merely rely on — SumUp, Supabase, Cloudflare — are best reported directly to them. Not sure? Report it to us and we'll work out where it belongs.

What happens after your report

  1. You receive an acknowledgement with a reference.
  2. We reproduce and assess the severity.
  3. If the vulnerability turns out to be actively exploited, we're legally required to report that within 24 hours to the designated CSIRT and ENISA (Article 14 of Regulation (EU) 2024/2847). That happens independently of your report and changes nothing about our commitments to you.
  4. We develop and test a fix.
  5. We roll it out and inform affected users.
  6. We then publish the details, crediting the reporter unless they'd rather stay anonymous.

Supported versions

Will be filled in here once our support policy is finalized.

Fixed vulnerabilities

Vulnerabilities we have fixed are published with a description, the impact, and what you need to do.

View the security advisories →

Why this page exists

Regulation (EU) 2024/2847 (the Cyber Resilience Act) requires us to have a single point of contact through which you can communicate directly and quickly with us about vulnerabilities, and a policy for coordinated vulnerability disclosure. This is that point of contact — also available in machine-readable form at /.well-known/security.txt.

Report a vulnerability

Name and email are optional — you can report fully anonymously.

The form is never the only way to reach us — feel free to call or email directly instead.