Trust & compliance
Responsible Disclosure
How security researchers can report potential vulnerabilities in FNI Solutions services safely and in good faith.
Last updated: 8 July 2026
Scope
This policy applies to security vulnerabilities affecting https://www.fni-solutions.be and related FNI SRL-operated services, unless a specific service policy states otherwise.
How to report
Send reports to security@fni-solutions.be. If unavailable, use contact@fni-solutions.be with subject line "Security disclosure".
Please provide sufficient detail for us to reproduce and assess the issue.
- Affected URL, system, or component
- Steps to reproduce
- Impact assessment
- Proof-of-concept if available (non-destructive)
- Your contact details for follow-up
What we ask from researchers
Act in good faith, avoid privacy violations, and give us reasonable time to investigate and remediate before any public disclosure.
- Do not access, modify, delete, or exfiltrate data
- No denial-of-service attacks
- No spam or social engineering
- No physical attacks
- No persistence on systems
- No public disclosure before coordination
What we commit to
We will acknowledge reports within a reasonable time, investigate in good faith, and aim to avoid legal action against good-faith reports that respect this policy.
Out of scope
The following are generally out of scope unless they demonstrate a clear, exploitable security impact on FNI SRL systems:
- Missing security headers without demonstrated exploit
- Rate limiting on non-sensitive endpoints
- Social engineering of staff or customers
- Physical security issues unrelated to our digital services
- Issues in third-party services outside FNI SRL control
Safe testing
Use non-destructive testing only. Do not degrade service availability or compromise user data.