Security and responsible disclosure

Last updated: October 9, 2026

The security of our users matters to us. If you find a vulnerability in TheorieWin, we would be grateful if you reported it to us responsibly, so we can fix it before anyone exploits it. We follow the Coordinated Vulnerability Disclosure (CVD) guideline of the Dutch National Cyber Security Centre (NCSC).

How to report

Email security@theoriewin.com and, if you can, include:

You can write in Spanish, English, Dutch or Portuguese. Do not send other people’s personal data: if you need to show data to demonstrate the problem, use the data of your own test account.

You will also find these details in our security.txt file.

In scope

Out of scope

Rules for research

Our commitment

No action against good-faith research

If you act in good faith and follow these rules, we will not file a criminal complaint or take legal action against you for your research. We consider your research authorised and, if a third party makes a claim because of it, we will make that clear. This does not apply if you act with bad intent, for example to obtain data, cause damage or ask for money in exchange for not publishing a problem.

Back to home