Security policy
Version 0.1 (draft), 6 October 2026
Found something? Tell us. Gforce Networks advises organisations on security, so we want to hear about weaknesses in our own systems before anyone else does.
Reports are welcome in English, Dutch or Portuguese. Machine-readable contact details are at
/.well-known/security.txt. Encrypted submission is available on request.What to include
- The affected system: URL, hostname or component.
- What the weakness is and what an attacker could do with it.
- Steps to reproduce, or a proof of concept.
- How to reach you, and whether you want to be credited by name or handle.
In scope
gforcenetworks.be, includingwwwand any other subdomain we serve
Out of scope
- Systems belonging to our clients. Those need the client's own written permission.
- Denial-of-service tests and automated high-volume scanning.
- Social engineering, phishing and physical attacks.
- Third-party providers such as Cloudflare and Google. Report those to the provider.
- Low-impact findings without a demonstrated risk: missing headers, version banners, self-XSS.
Rules of engagement
- Test only as far as needed to confirm the weakness.
- Do not read, change or delete data that is not yours.
- Leave nothing behind and do not move on to other systems.
- Keep the service available.
- Keep the details confidential until we have agreed a fix and a disclosure date.
- We do not run a paid bug bounty and do not respond to payment demands.
What you can expect from us
| Step | When |
|---|---|
| Acknowledgement | Within 3 business days |
| Initial assessment and severity rating | Within 10 business days |
| Progress updates | At least every 14 days |
| Fix target | 30 days for critical and high severity, 90 days otherwise |
| Public disclosure | Coordinated with you, normally within 90 days |
With your agreement we credit you by name or handle.
Safe harbour
If you act in good faith and within this policy, we will not take legal action or file a complaint against you.
Belgian law also protects ethical hackers under the NIS2 law of 26 April 2024, articles 22 and 23, provided its conditions are met. The conditions include acting without harmful intent, doing no more than is needed to confirm the weakness, not disclosing it publicly, and notifying both the affected organisation and the Centre for Cybersecurity Belgium (CCB) within the deadlines set by the law. See the CCB website for its current guidance.
How we handle your report
We use your contact details only to handle the report and keep the report for 3 years after it is closed. See the privacy notice.