Security
Report clearly. Contain quickly. Learn visibly.
How we receive reports and how security is built into delivery.
Report a vulnerability
Email info@soswebsite.nl with the affected URL, reproduction steps and impact. Do not access data that is not yours, disrupt availability or publish before coordinated disclosure.
Acknowledgement
We aim to acknowledge a credible report within two working days and agree a practical update rhythm.
Access control
Project access uses named accounts, 2FA where available, least privilege, logged changes and explicit offboarding.
Delivery safeguards
Code review, dependency review, automated checks, staging, backups, rollback and monitoring are selected in proportion to risk.
Continuity
Critical deployment steps and repositories must be transferable; no production system should depend on one person’s private machine.
Last materially updated: 24 August 2026.