Skip to content

Security policy

Reporting a vulnerability.

Found a security issue in Schaduwplan? Report it — we take every report seriously, respond within fixed timelines, and take no legal action against good-faith research. This page describes how that works.

Last updated: 2 August 2026

This is an English translation for convenience. The legally binding version is the Dutch one.

What this policy covers

This policy covers the web application at schaduwplan.nl, its API, and the serverless functions served under schaduwplan.nl.

Third-party services we use but do not operate — PDOK, the 3DBAG API, Ellipsis Drive, Cloudflare, Supabase, Stripe, Sentry and PostHog — fall under those parties' own policies. See Third-party components below for what we do when a report concerns one of them.

How to report

Send your report to [email protected]. That is the same address as in our security.txt (RFC 9116). We have no PGP key; if you need to share something confidential, say so in your first email and we will agree on a channel.

Reports are accepted in Dutch or English. Help us by describing what the problem is, how we can reproduce it, and what impact you expect.

What we commit to

  • We acknowledge receipt within 3 business days.
  • We give an initial assessment within 10 business days: accepted, duplicate, or out of scope.
  • After that we send a status update every 14 days until the report is resolved.
  • We fix it — or limit the impact — without undue delay, prioritised by severity.
  • Once a fix or mitigation is available, we disclose the vulnerability publicly. We coordinate the timing with the reporter.

Safe harbour

We will not pursue legal action over good-faith security research that:

  • respects user privacy and data;
  • does not degrade the availability of the service;
  • does not retrieve more data than needed to demonstrate the issue;
  • gives us reasonable time to remediate before public disclosure.

Third-party components

If the vulnerability is in a component we use but do not build ourselves, we report it to its maintainer and coordinate our advisory with theirs.

Recognition

On request we credit you by name in the advisory about the fixed vulnerability. We pay no monetary reward — Schaduwplan has no bug-bounty programme.

Questions about this page? Email [email protected]. For data processing, see the privacy statement.