Coordinated Vulnerability Disclosure Policy

In short
At Zeticon, we take the security of our systems seriously. Despite our efforts, it is still possible that a weakness exists.
If you have found a vulnerability in one of our systems, we would like to hear about it so we can take action as quickly as possible. We want to work with you to better protect our customers and our systems.
We ask you to:
- Submit your findings via our vulnerability report form, at the bottom of the page . Where the form supports a secure/encrypted attachment upload, please use it to prevent this information from falling into the wrong hands;
- Not abuse the problem, e.g. by downloading more data than necessary to demonstrate the vulnerability, or accessing, deleting or modifying data belonging to third parties;
- Not share the problem with others until it has been resolved, and delete any confidential data obtained through the vulnerability immediately after reporting;
- Not use attacks on physical security, social engineering, distributed denial of service, spam, or third-party applications;
- Provide enough information to reproduce the problem so we can resolve it as quickly as possible (usually the IP address or URL of the affected system and a description of the vulnerability are sufficient, but more complex vulnerabilities may require more detail).
What we promise:
- We will respond to your report within 5 business days with our assessment and an expected timeline for a fix;
- If you have complied with the above conditions, we will not take legal action against you regarding the report;
- We will treat your report confidentially and will not share your personal data with third parties without your consent, unless necessary to comply with a legal obligation. Reporting under a pseudonym is possible;
- We will keep you informed of our progress in resolving the problem;
- Zeticon does not currently operate a paid reward program (see section 2(f) below).
We aim to resolve every reported problem as quickly as possible, and we welcome your involvement in any publication about the issue once it has been resolved.
The full legal terms of this Coordinated Vulnerability Disclosure Policy, including scope, mutual obligations, the reporting procedure, and applicable Belgian law, are set out below.
1. Scope of the policy
In order to improve the performance and security of our networks and information systems, Zeticon has adopted this coordinated vulnerability disclosure policy. This policy gives participants ("ethical hackers") the opportunity to search, with good intentions, for potential vulnerabilities in the Organisation's systems, equipment and products, or to pass on any information they discover about a vulnerability.
Access to our IT systems and equipment is only permitted with the intention of improving security and informing us of existing vulnerabilities, and strictly in compliance with the other conditions set out in this document. Our policy concerns security vulnerabilities that could be exploited by third parties or disrupt the proper functioning of our products, services, networks or information systems.
In scope:
- The MediaHaven platform (SaaS/hosted environments operated by Zeticon)
- eSignHaven, insofar as the vulnerability lies in components Zeticon itself operates or configures (integration layer, authentication, tenant configuration, hosting infrastructure)
- Zeticon-managed infrastructure and public-facing domains/subdomains:
- zeticon.com
- mediahaven.com
- esignhaven.com
Out of scope:
- Denial-of-service testing of any kind
- Physical security, social engineering, or phishing against Zeticon staff or customers
- Findings from automated scanning without manual validation, or issues with no demonstrable security impact
Systems that depend on third parties are excluded from the scope of this policy, unless the third party has explicitly agreed to these rules in advance. The following systems, used by Zeticon and depending on third parties, are excluded from this policy:
- Underlying cloud provider infrastructure outside Zeticon's own configuration
A participant's research on information systems not explicitly included within the scope of this policy could lead to legal proceedings against them.
2. Mutual obligations of the parties
a) Proportionality
The participant undertakes to comply strictly with the principle of proportionality in all their activities and not to disrupt the availability of the services provided by the system, and not to make use of the vulnerability beyond what is strictly necessary to demonstrate the security flaw. If the security problem has been demonstrated on a small scale, no further action should be taken. This policy does not intend to allow intentional access to the content of computer data, communication data or personal data; such access may only occur incidentally in the course of searching for vulnerabilities.
b) Actions that are not allowed
Participants are not permitted to:
- copy, alter or delete data from the IT system;
- change IT system parameters;
- install malware (viruses, worms, Trojan horses, etc.);
- carry out Distributed Denial of Service (DDoS) attacks;
- carry out social engineering attacks;
- carry out phishing attacks;
- carry out spamming;
- steal passwords or carry out brute-force attacks;
- install a device to intercept, store or learn of (electronic) communications that are not accessible to the public;
- intentionally intercept, store or receive communications not accessible to the public;
- deliberately use, maintain, communicate or distribute the content of non-public communications or of data from an IT system where the participant should reasonably have known it had been obtained unlawfully.
If a participant wishes to use the assistance of a third party to carry out their research, the participant must ensure that the third party is aware of this policy and agrees, by offering assistance, to abide by its terms.
c) Confidentiality
The participant must strictly refrain from sharing or disclosing any information collected under this policy with third parties without Zeticon's prior and explicit consent. It is likewise not permitted to reveal or disclose computer data, communication data or personal data to third parties. Where a vulnerability may also affect other organisations in Belgium, the participant or Zeticon may nevertheless inform the CCB (vulnerabilityreport@ccb.belgium.be).
d) Bonafide execution
Zeticon undertakes to implement this policy in good faith and not to take civil or criminal legal action against a participant who complies with its conditions. The participant must be free of fraudulent intent, intent to harm, or intent to use or damage the visited system or its data (this also applies to third-party systems located in Belgium or abroad). If there is any doubt about any of the conditions of this policy, the participant must first contact Zeticon's point of contact and obtain written consent before acting.
e) Processing of personal data
The purpose of this CVDP is not to intentionally process personal data, but it is possible that a participant may incidentally process personal data in the course of vulnerability research. Should this occur, the participant undertakes to:
- process personal data only in accordance with this policy and exclusively to investigate vulnerabilities in Zeticon's systems, equipment or products;
- limit such processing to what is strictly necessary for that purpose;
- ensure anyone assisting them respects confidentiality or is bound by an appropriate legal confidentiality obligation;
- implement appropriate technical and organisational security measures (e.g. encryption) appropriate to the risk;
- assist Zeticon, where relevant, with data-subject rights requests, security of processing, and impact assessments;
- inform Zeticon of any personal data breach as soon as possible after becoming aware of it, via the reporting channel described in section 3(a);
- not retain any processed personal data longer than necessary, store it securely in the meantime, and delete it immediately once their participation ends;
- keep a register of the categories of processing activities carried out, in accordance with art. 30 §2 GDPR, if applicable.
A participant working with a third party must ensure that third party agrees to these same terms and remains fully responsible to Zeticon if that third party fails to meet its data-protection obligations. A participant who processes personal data inconsistently with this policy, or for purposes other than investigating a vulnerability, will be considered a data controller in their own right and assumes full responsibility for that processing.
f) Reward
Zeticon does not offer a monetary or in-kind reward under this policy. Any request for a reward will be considered an unlawful attempt at extortion.
3. How to report a vulnerability
a) Point of contact
Reports should be submitted exclusively via our vulnerability report form, bottom of the page.
b) Information to communicate
As soon as possible after discovery, send us your findings using the form.
4. Procedure
a) Discovery
Where a participant becomes aware of a potential vulnerability, they should, where possible, carry out prior checks to confirm its existence and identify the risks involved.
b) Notification
The participant undertakes to notify technical information on a possible vulnerability, as soon as possible, to the point of contact listed under 3(a), using the designated secure means of communication. Upon receipt, Zeticon undertakes to send the participant an acknowledgement of receipt within 5 business days, with an internal reference where possible, a reminder of the main obligations of this policy, and the next steps.
c) Communication
Both parties undertake to make every effort to ensure continuous and effective communication. In the absence of a reaction from either party within a reasonable time, either party may call upon the Centre for Cybersecurity Belgium (CCB) as coordinator by default (vulnerabilityreport@ccb.belgium.be).
d) Investigation
Zeticon will attempt to replicate the reported environment and behaviour to verify the finding, and will keep the participant informed on a regular basis of the results and follow-up. Zeticon will assess the severity and exploitability of the vulnerability, and check for related or similar reports and other affected systems.
e) Development of a solution
Taking into account the state of the art, implementation cost, severity of risk to users, and technical constraints, Zeticon will aim to develop a solution within 90 calendar days. Positive tests (solution works as intended) and negative tests (solution does not disrupt other functionality) will be carried out before deployment.
f) Possible public disclosure
Zeticon will decide, in coordination with the participant, on the modalities for eventually making the vulnerability public. Public disclosure should take place as early as possible, together with deployment of the solution and a security notice to users. Where a vulnerability also affects other organisations, Zeticon must inform the CCB (vulnerabilityreport@ccb.belgium.be) in any case, even if it does not want the vulnerability disclosed publicly. Zeticon also commits to collecting feedback on the deployed solution and taking corrective measures for any compatibility issues that arise.
5. Law applicable
Belgian law applies to any disputes arising from the application of this policy. The CCB (vulnerabilityreport@ccb.belgium.be) may act as an intermediary to help reconcile Zeticon and a participant on matters relating to the application of this policy.
6. Duration
The rules of this policy apply from 11/09/2026 until modified or withdrawn by Zeticon. Any such change or withdrawal will be published on Zeticon's website and will apply automatically 30 days after publication.
Vulnerability report form
Form
Provide enough information to enable us to reproduce the problem and resolve it as quickly as possible. Please provide at least the following:
What do we do with your personal data?
Please read our privacy policy.
Transfer of personal data by the participant to a country outside the EU/EEA
To be completed if necessary, using the Standard Contractual Clauses of Commission Implementing Decision (EU) 2021/914 of 4 June 2021, Annex I, for the transfer of personal data to third countries under Regulation (EU) 2016/679.
Related documentation:
- NIS-2 Law (26 April 2024), art. 22, 23 (legal vulnerability reporting procedure) and art. 30, §3, 11° (obligation to adopt a CVD policy)
- CCB Vulnerability reporting to the CCB: https://ccb.belgium.be/cert/vulnerability-reporting-ccb
- CCB Guide to Coordinated Vulnerability Disclosure Policies (Part I: Good Practices, Part II: Legal Aspects)