Responsible Disclosure Document
This document defines anDREa B.V.’s public stance on vulnerability reporting. It outlines the explicit boundary conditions under which we welcome security reports, establishing our Safe Harbor protections in alignment with ISO 27001:2023 (A.05.24, A.08.08 - Management of Technical Vulnerabilities) and NIS 2 (Article 21(2)(e) - Vulnerability Handling & Disclosure) guidelines.
1. Context & Operational Boundaries
anDREa B.V. deeply values the contributions of users and security researchers who help maintain the security posture of the myDRE ecosystem. To ensure legal clarity and operational safety, we distinguish between standard, authorized use and unauthorized scanning:
- Coordinated Vulnerability Disclosure (CVD): The formal, structured process through which security vulnerabilities are discovered, reported, remediated, and, when appropriate, publicly disclosed in a synchronized, controlled manner (Coordinated Vulnerability Discosure Policy).
- Scope Restriction: Our Coordinated Vulnerability Disclosure Policy applies strictly and exclusively to vulnerabilities identified passively during the normal, legitimate, and authorized utilization of anDREa B.V. services.
2. Prohibited Actions & System Telemetry
This document does not constitute an open invitation or authorization to conduct proactive security testing against our infrastructure.
Strictly Prohibited Actions
- Proactively or aggressively scanning our networks, endpoints, or perimeter boundaries.
- Probing, stress-testing, or launching Denial of Service (DoS) simulations against platform components.
- Executing independent penetration testing or black-box security assessments.
- Reverse-engineering, decompiling, or disassembling any portion of the myDRE source code or platform layers.
Operational Enforcement
anDREa continuously monitors its cloud networks and system telemetries. Automated vulnerability or port scans will trigger immediate security alerts. These events are systematically investigated by our security operations function as potential malicious activity. Unauthorized testing incurs unnecessary investigation costs and forces administrative or legal remediation actions that disrupt standard operations.
3. Safe Harbor Limitations
Safe Harbor Exclusion Notice: Safe Harbor legal protections do not extend to any individual, group, or organization that engages in proactive network scanning, system probing, reverse-engineering, or unauthorized penetration testing without explicit, prior written authorization from anDREa B.V. management.
To ensure your report is handled under our protected disclosure framework, please refer to the complete submission protocols and communication channels detailed within our primary Coordinated Vulnerability Discosure Policy.