Gforce Networks
Vulnerability disclosure

Security policy

Version 0.1 (draft), 6 October 2026

Found something? Tell us. Gforce Networks advises organisations on security, so we want to hear about weaknesses in our own systems before anyone else does.

Report to [email protected]
Reports are welcome in English, Dutch or Portuguese. Machine-readable contact details are at /.well-known/security.txt. Encrypted submission is available on request.

What to include

In scope

Out of scope

Rules of engagement

What you can expect from us

StepWhen
AcknowledgementWithin 3 business days
Initial assessment and severity ratingWithin 10 business days
Progress updatesAt least every 14 days
Fix target30 days for critical and high severity, 90 days otherwise
Public disclosureCoordinated with you, normally within 90 days

With your agreement we credit you by name or handle.

Safe harbour

If you act in good faith and within this policy, we will not take legal action or file a complaint against you.

Belgian law also protects ethical hackers under the NIS2 law of 26 April 2024, articles 22 and 23, provided its conditions are met. The conditions include acting without harmful intent, doing no more than is needed to confirm the weakness, not disclosing it publicly, and notifying both the affected organisation and the Centre for Cybersecurity Belgium (CCB) within the deadlines set by the law. See the CCB website for its current guidance.

How we handle your report

We use your contact details only to handle the report and keep the report for 3 years after it is closed. See the privacy notice.