Cyber Safety

Responsible disclosure

Despite our security efforts a weakness could occur in one of our systems. If you have detected a vulnerability, please let us know. Then we can take the necessary measures as soon as possible, working together with you in an ongoing effort to keep our systems secure.

The Responsible disclosure (Dutch; English from October 23rd) procedure describes how to report a detected vulnerability.

We accept reports of real vulnerabilities in applications and / or systems. Cases such as the lack of RRs (SPF, CAA and the like) and security headers in websites (HSTS, Content-Security-Policy and the like) are not considered reports. These cases are known to us and are already being worked on.

A responsible disclosure can be reported using the relevant email address: responsible-disclosure@utwente.nl.

We want to thank everybody who reported a vulnerability in a responsible way in our Hall of Fame.