Found something? We want to hear about it.

Found a vulnerability in Core, our clusters or a service running on it, even one belonging to one of our customers? Report it to us: an engineer will look at it, and no lawyers will show up at your door.

Report a vulnerability

Email us at security@rual.nl, encrypted if you can. Describe what you found, where you found it, and how we can reproduce it. A screenshot or a short proof of concept helps us enormously.

Seeing active abuse or immediate danger? Call our emergency line straight away: +31 (0)10 300 67 78. It is answered 24 hours a day.

Prefer a form? There is one further down this page.

Reply

within two working days, from an engineer

Fix

timed to the severity of the finding

Credit

by name, if you want it

Last updated

24 July 2026

How it works

  1. You report, we confirm

    Within two working days you get a reply from an engineer, not a ticket robot. We keep you posted right through to the fix.

  2. We fix it, across the platform

    Security fixes roll out automatically to every Core environment. One report therefore protects all of our customers at once.

  3. You get the credit

    If you want to be named, we name you with thanks. For serious findings we show our appreciation in more concrete ways too.

The ground rules

Short, and binding on both sides.

What we ask of you

Report your finding as soon as you can and do not share it with others until it is fixed. Go no further than you need to in order to demonstrate the problem. Do not copy, change or delete data; no social engineering, spam or DDoS.

What we promise you

No legal action if you stick to these ground rules. We treat your report confidentially and do not share your details without permission. You hear from us what we are doing with it, from first reply to fix.

Out of scope. Vulnerabilities in third-party services, missing best-practice headers without demonstrable impact, and findings from automated scanners without a working proof of concept.

File a report

We acknowledge every report within two working days. That acknowledgement says nothing yet about the severity or the validity of what you reported.

We use your details only to handle this report and to get back to you.

Not a hacker, just curious now?

You do not have to break anything to look inside: a test environment on Core is free, no credit card.