Security and responsible disclosure
The security of our users matters to us. If you find a vulnerability in TheorieWin, we would be grateful if you reported it to us responsibly, so we can fix it before anyone exploits it. We follow the Coordinated Vulnerability Disclosure (CVD) guideline of the Dutch National Cyber Security Centre (NCSC).
How to report
Email security@theoriewin.com and, if you can, include:
- what you found and where (URL, screen or request);
- the steps to reproduce it;
- what an attacker could achieve (the impact);
- how to contact you, if it is not the same address.
You can write in Spanish, English, Dutch or Portuguese. Do not send other people’s personal data: if you need to show data to demonstrate the problem, use the data of your own test account.
You will also find these details in our security.txt file.
In scope
- theoriewin.com and www.theoriewin.com, including the study app (
/en/app/and the other languages) - api.theoriewin.com
- Issues such as: accessing other people’s data or accounts, bypassing authentication, injection (XSS, SQL), CSRF with a real effect, leaks of personal data, privilege escalation or misconfigurations that can be exploited
Out of scope
- Denial-of-service (DoS) attacks and load testing
- Social engineering, phishing or spam aimed at us or our users
- Physical attacks on our equipment
- Third-party services such as Cloudflare, Brevo or Google (report to them directly)
- Results from automated scanners without a demonstrated impact
- Security headers or email records (SPF, DKIM, DMARC) that could be improved but without a practical attack
- Clickjacking on pages without sensitive actions, self-XSS or issues that only affect unsupported browsers
- Rate limits on routes that do not handle sensitive data
Rules for research
- Only use your own test accounts. Do not access, change or delete other people’s data beyond the minimum needed to demonstrate the problem.
- If you come across other people’s personal data, stop, do not keep it and let us know right away.
- Do not use automated tools that generate a lot of traffic, and do not try to bypass the bot protection on a large scale.
- Do not publish or share the problem until we have fixed it or until 90 days have passed since your report, whichever comes first. If we need more time, we will agree on it with you.
Our commitment
- We confirm that we have received your report within 5 working days.
- We give you a first assessment within 10 working days and keep you updated until the problem is fixed.
- We fix problems according to their severity, as soon as possible.
- If you want, we mention your name once the problem is fixed. We do not offer financial rewards.
- We process your data only to handle your report, in line with our privacy policy.
No action against good-faith research
If you act in good faith and follow these rules, we will not file a criminal complaint or take legal action against you for your research. We consider your research authorised and, if a third party makes a claim because of it, we will make that clear. This does not apply if you act with bad intent, for example to obtain data, cause damage or ask for money in exchange for not publishing a problem.