Security
Responsible Disclosure
Security is our profession — which is exactly why we know no system is flawless. Found a vulnerability in our systems? Let us know. We treat every report seriously and confidentially, and take no legal action against researchers who follow the rules below.
Last updated: August 2026
Immediate danger or an ongoing incident? State this clearly in your email subject with the word URGENT and we will prioritise your report.
Does it concern a client's OT or ICS environment? Report it only to us, not to the client concerned. A vulnerability in an industrial environment can affect physical safety; we will ensure careful, coordinated handling.
1. What this policy covers
This policy applies to systems and services under our own responsibility:
- the website jmnl.nl and its subdomains;
- the email infrastructure of the jmnl.nl domain;
- software, firmware and hardware solutions developed and delivered by JMNL Innovation.
Found a vulnerability in a system belonging to one of our clients? Please report it to us as well, even if the system is not managed by us. We will then arrange a coordinated report to the right party.
2. What falls outside this policy
We do not process the following reports. In practice they do not represent a usable security risk, or they require actions we do not wish to encourage:
- vulnerabilities in third-party software or services that we do not manage ourselves (report those to the supplier concerned);
- reports consisting solely of automated scanner output, without demonstrated impact;
- missing security headers, cookie flags or best practices without demonstrable consequence;
- SPF, DKIM or DMARC configuration, unless you demonstrate that spoofing is actually possible;
- weak or outdated TLS suites without a working attack scenario;
- rate limiting on public pages, unless it leads to a concrete risk;
- self-XSS, clickjacking on pages without sensitive actions, and issues that only occur in outdated or unsupported browsers;
- social engineering, phishing or approaching our staff or clients;
- physical attacks on our offices or equipment;
- (distributed) denial-of-service, stress testing and spam.
3. What we ask of you
So that we can handle your report without harm being done, we ask you to observe the following rules:
- Do no damage. Go no further than strictly necessary to demonstrate the vulnerability.
- Leave data alone. Do not modify, delete or download data belonging to us or to third parties. If you unintentionally come across personal data, stop immediately, report it and delete the data.
- No denial-of-service. Do not run stress or load tests and do not install a backdoor, not even to demonstrate access.
- Stay out of OT environments. Never carry out active tests on industrial systems, PLCs or control networks. In that case describe your finding theoretically and contact us first.
- No brute force or automated scans. Do not use tools that generate large volumes of traffic.
- Share nothing with others while the vulnerability is unresolved, and publish no details.
- Report promptly after making your finding, and give us reasonable time to respond.
- Provide enough information for us to reproduce the issue.
If you observe these rules, we will take no legal action against you in response to the report, and we will not report you to the authorities. We cannot, however, guarantee that third parties — such as a client or the Public Prosecution Service — will take the same view if you do not follow the rules or have been active outside our systems.
4. How to report
Send your report by email to security@jmnl.nl. Please do not report a vulnerability through the ordinary contact form or via social media.
Please include as much of the following as possible:
- the type of vulnerability and the affected system, domain or component;
- a clear, step-by-step description allowing us to reproduce the issue;
- evidence such as requests, responses, screenshots or a concise proof-of-concept;
- the potential impact as you assess it;
- the date and time of your research and the IP address you tested from — this lets us find your traffic in our logs and distinguish it from malicious traffic;
- contact details where we can reach you, and whether you wish to be named on publication.
You may report anonymously. Bear in mind that we then cannot ask questions or keep you informed about how the report is handled.
Would you like to send your report encrypted? Request our current PGP key via security@jmnl.nl; we will send it along with its fingerprint on request.
5. What we promise you
| Step | Timeframe |
|---|---|
| Acknowledgement of your report | Within 3 working days |
| Substantive response with our assessment and an expected resolution time | Within 10 working days |
| Interim status update while the report is open | At least every 3 weeks |
| Notification once the vulnerability has been resolved | Immediately after resolution |
In addition, we undertake to:
- treat your report confidentially and not share your personal data with third parties without your consent;
- keep you informed of progress;
- decide together with you whether, when and how the vulnerability is published;
- take no legal action where you have observed the rules.
6. Publication and credit
We aim for coordinated disclosure. Our starting point is that a vulnerability is made public only after it has been resolved, and at the latest 90 days after your report. For a vulnerability in an OT or ICS environment that period may be longer by agreement: patching in an industrial environment often requires a scheduled maintenance window.
If you would like us to, we will name you as the discoverer of the vulnerability on publication. If you indicate you wish to remain anonymous, we will respect that.
7. Rewards
JMNL Innovation is a small, specialised business and does not operate a bug bounty programme. We therefore offer no monetary reward. What we do offer: serious, substantive handling of your report by people who know the field, a genuine expression of appreciation and — if you wish — public credit.
8. security.txt
Our contact details for security reports are also available in machine-readable form according to RFC 9116, at /.well-known/security.txt:
Contact: mailto:security@jmnl.nl Expires: 2027-08-16T00:00:00.000Z Preferred-Languages: nl, en Canonical: https://jmnl.nl/.well-known/security.txt Policy: https://jmnl.nl/en/responsible-disclosure.html
Thank you for taking the time to make the internet — and the industrial systems attached to it — a little safer.