Report a vulnerability
We take security reports seriously and appreciate you taking the time to file one.
Pick whatever works best for you
You don't have to identify yourself. Anonymous reporting is possible through the form, and you can also report indirectly via the Centre for Cybersecurity Belgium (CCB), which acts as coordinator for coordinated vulnerability disclosure. Centre for Cybersecurity Belgium (CCB)
Please don't report via a public issue or on social media, and don't publish before we've been in touch. That gives users a chance to update first.
What to include
If you can, please include:
- Which component it concerns (see Scope below) and which version
- How to reproduce the vulnerability
- What an attacker could achieve with it
What you can expect from us
- Acknowledgement
- within 2 business days
- Initial assessment
- within 5 business days
- Status update
- at least every 2 weeks while the report is open
- Publication
- only once a fix is available and users have had a chance to apply it
These are commitments, not targets.
We're happy to credit responsible reporters when we publish the fix, unless you'd rather stay anonymous. We don't run a bug bounty program, so we offer recognition but no reward.
Scope
This reporting channel covers Wassalon-kassa as we deliver it, which is more than just the till:
- Till software on the Raspberry Pi
- Kiosk app on the customer tablet
- Cloud layer (database, functions, realtime)
- Owner app my.wassalonkassa.be
- Fleet app fleet.wassalonkassa.be
- This marketing website (wassalonkassa.be)
Vulnerabilities in third-party software we ship also belong here. We report those onward to whoever maintains the component, and fix our side of it.
Third-party services we merely rely on — SumUp, Supabase, Cloudflare — are best reported directly to them. Not sure? Report it to us and we'll work out where it belongs.
What happens after your report
- You receive an acknowledgement with a reference.
- We reproduce and assess the severity.
- If the vulnerability turns out to be actively exploited, we're legally required to report that within 24 hours to the designated CSIRT and ENISA (Article 14 of Regulation (EU) 2024/2847). That happens independently of your report and changes nothing about our commitments to you.
- We develop and test a fix.
- We roll it out and inform affected users.
- We then publish the details, crediting the reporter unless they'd rather stay anonymous.
Supported versions
Will be filled in here once our support policy is finalized.
Fixed vulnerabilities
Vulnerabilities we have fixed are published with a description, the impact, and what you need to do.
View the security advisories →Why this page exists
Regulation (EU) 2024/2847 (the Cyber Resilience Act) requires us to have a single point of contact through which you can communicate directly and quickly with us about vulnerabilities, and a policy for coordinated vulnerability disclosure. This is that point of contact — also available in machine-readable form at /.well-known/security.txt.
Report a vulnerability
Name and email are optional — you can report fully anonymously.