---
title: Responsible disclosure
description: Found a vulnerability in Core, our clusters or a system running on it? Report it to security@rual.nl. An engineer replies in two working days, no ticket robot.
url: "https://rual.nl/en/responsible-disclosure"
locale: en
alternate: "https://rual.nl/responsible-disclosure"
updated: 2026-08-03
source: "https://rual.nl"
---

[Security](https://rual.nl/en/security) > Responsible disclosure

# Found something? We want to hear about it.

We take the security of our systems extremely seriously, but no system is perfect. Have you found a vulnerability in Core, in our clusters or in one of our services? Or in a system running on Core, even if it belongs to one of our customers? Report it to us: we always want to look at it, and we make sure it reaches the right place. We value your help. No lawyers at the door.

[Email security@rual.nl](mailto:security@rual.nl)

[How security is built in](https://rual.nl/en/security)

## Report a vulnerability

Email us at [security@rual.nl](mailto:security@rual.nl), encrypted if you can. Describe what you found, where you found it, and how we can reproduce it. A screenshot or a short proof of concept helps us enormously.

Seeing active abuse or immediate danger? Call our emergency line straight away: [+31 (0)10 300 67 78](tel:+31103006778). It is answered 24 hours a day.

| Term | Def |
| --- | --- |
| Reply | within two working days, from an engineer |
| Fix | timed to the severity of the finding |
| Credit | by name, if you want it |
| Last updated | 24 July 2026 |

## How it works

1. **You report, we confirm** — Within two working days you get a reply from an engineer, not a ticket robot. We keep you posted right through to the fix.
2. **We fix it, across the platform** — Security fixes roll out automatically to every Core environment. One report therefore protects all of our customers at once.
3. **You get the credit** — If you want to be named, we name you with thanks. For serious findings we show our appreciation in more concrete ways too.

## The ground rules

Short, and binding on both sides.

- **What we ask of you** — Report your finding as soon as you can and do not share it with others until it is fixed. Go no further than you need to in order to demonstrate the problem. Do not copy, change or delete data; no social engineering, spam or DDoS.

- **What we promise you** — No legal action if you stick to these ground rules. We treat your report confidentially and do not share your details without permission. You hear from us what we are doing with it, from first reply to fix.

**Out of scope.** Vulnerabilities in third-party services, missing best-practice headers without demonstrable impact, and findings from automated scanners without a working proof of concept.

## Not a hacker, just curious now?

You do not have to break anything to look inside: a test environment on Core is free, no credit card.

[Request a test environment](https://rual.nl/en/pricing)

[How security is built in](https://rual.nl/en/security)
