Security
Reporting a vulnerability in this website
If you find a security issue in blaeu.com, please email rob@blaeu.com . Encrypt with the PGP key below if the details are sensitive. Please do not access other people's data, degrade the service, or disclose the issue publicly before it is fixed. This is not a bug bounty programme and no rewards are offered.
Security contact: Rob van Eijk, director, Blaeu Privacy Response Team B.V.
Vulnerabilities in third-party systems and code
Our work includes analysing software, websites and data flows for research and for expert-witness work for clients. If that work reveals a vulnerability in someone else's system, we handle it as follows:
- Report it first to the vendor or the responsible CSIRT, privately.
- Allow a reasonable time to fix it, agreed case by case.
- Publish only after the fix.
For client engagements this happens within the confidentiality terms of the engagement and applicable law.
PGP key and security.txt
Fingerprint: 6E9C 7952 DA11 3DB1 1F1A 9411 9B91 7133 4B4F 58DE
Public key (SURFnet keyserver) | security.txt
Languages: English, Dutch.