Responsible Disclosure
At Interstellar, security is always a top priority. We do everything we can to protect our systems and data, but it’s possible that a vulnerability might still be found. If you happen to discover one, we’d really appreciate it if you let us know — so we can act quickly and keep our environment safe for everyone.
We regularly test and review our systems ourselves, so there’s no need for others to actively look for vulnerabilities. Actively scanning or probing our systems without permission isn’t appreciated. But if you stumble upon something by accident, we’d be grateful if you report it responsibly.
How to report a vulnerability
Please send your findings as soon as possible to security@interstellar.nl
When you do, we ask that you:
- Don’t exploit the issue — for example, by downloading more data than needed to show the problem, or by viewing, deleting, or changing information belonging to others.
- Keep the issue to yourself until it’s been resolved, and delete any confidential data you may have obtained right after the fix.
- Don’t perform attacks on physical security, use social engineering, DDoS attacks, spam, or third-party applications.
- Don’t use vulnerability scanners or software that actively tests our systems.
- Provide enough detail so we can reproduce and fix the issue. Usually, an IP address or URL and a short description are enough, but for more complex cases, we might need extra information.
What we promise:
- We’ll respond to your report within three working days, with our initial assessment and an estimated timeline for resolving the issue.
- If you’ve followed the guidelines above, we won’t take any legal action related to your report.
- We’ll treat your report confidentially and won’t share your details without your permission (unless required by law). You can also report anonymously if you prefer.
- We’ll keep you updated on our progress.
- If you’d like to be credited as the discoverer, we’ll gladly mention your name in any related communication.
- We aim to handle all reports as quickly as possible and would appreciate being involved in any planned publication.
This responsible disclosure policy is based on the example text by Floor Terra, available at
Responsible Disclosure