Security
Security reports are welcome. A clear report, handled early and in good faith, gives everyone more room to fix the problem well.
Proper Tools operates a deliberately small set of public systems and services. That does not make them immune to mistakes.
This page explains how to report a security issue, what is in scope, what Proper Tools asks of researchers, and what you can expect in return.
Proper Tools does not claim perfect security. The aim is to reduce avoidable exposure, detect problems, respond proportionately, and learn from what is found.
Report a security issue
Send security reports to security@propertools.be .
If that address is unavailable, use hello@propertools.be .
The machine-readable disclosure information is available at
/.well-known/security.txt
.
If the issue is being actively exploited or presents an immediate risk, put URGENT in the subject line and say briefly what is happening.
Proper Tools aims to acknowledge a report within two business days and provide an initial assessment within five business days. These are response targets rather than guarantees, but urgent reports are prioritised.
What makes a report useful
A report does not need to be polished. It should contain enough information to locate, reproduce, and assess the issue.
Where possible, include:
- the affected page, service, repository, or resource;
- a description of what you observed;
- steps needed to reproduce it;
- the likely security impact;
- whether you encountered personal data, credentials, or confidential material;
- any temporary measure that may reduce immediate harm; and
- your preferred name, contact details, and credit preference.
Screenshots, request and response examples, or short proofs of concept can help. Please redact information that is not necessary to demonstrate the issue.
Do not send live passwords, personal data, private keys, or large collections of sensitive material through ordinary email. Send a brief description first so that an appropriate transfer method can be agreed.
Scope
In scope
-
propertools.beand subdomains operated by Proper Tools; - public code, files, downloads, and repositories published under the Proper Tools name;
- exposed credentials, secrets, or personal data for which Proper Tools is responsible; and
- security problems caused by the way Proper Tools has configured or integrated an external service.
Out of scope
- vulnerabilities in a third-party service itself, rather than in the way Proper Tools uses it;
- social engineering, phishing, or impersonation;
- physical attacks against people, premises, or equipment;
- denial-of-service, load, or resource-exhaustion testing;
- spam, bulk account creation, or destructive automation; and
- accessing, altering, retaining, or exfiltrating more information than is necessary to demonstrate the issue.
Automated scanner output without a clear explanation of security impact may receive lower priority. A tool finding is most useful when accompanied by an account of what an attacker could actually do.
This policy does not authorise testing of systems operated by another organisation or access to data belonging to another person.
Good-faith research
Proper Tools considers research to be in good faith when it is intended to identify and report a security problem while avoiding unnecessary harm.
That means:
- working within the scope described above;
- using the minimum access needed to confirm the issue;
- avoiding disruption, persistence, and alteration of data;
- stopping and reporting promptly if you encounter personal data, confidential material, or live credentials;
- not using the issue for extortion or commercial pressure; and
- allowing reasonable time for assessment and remediation before public disclosure.
When research is conducted in good faith and in accordance with this policy, Proper Tools will not initiate legal action solely because of that research.
If you depart accidentally from the policy, explain what happened promptly and take reasonable steps to prevent further harm.
What Proper Tools will do
A report will be assessed on its substance, not on how formally it is written or who sends it.
When a report identifies a genuine issue, Proper Tools will:
- acknowledge the finding plainly;
- assess its impact and immediate risks;
- ask only for additional evidence reasonably needed to investigate;
- mitigate or correct the issue where possible;
- keep the reporter informed when there is meaningful progress to share;
- coordinate disclosure timing in good faith; and
- offer public credit unless the reporter prefers anonymity.
A report may also reveal that the issue lies outside Proper Tools, cannot be reproduced, or does not create a material security impact. In that case, the reasoning will be explained as clearly as the available information permits.
Coordinated disclosure
Please contact Proper Tools before publishing a vulnerability so that its impact can be assessed and affected systems or people can be protected.
The appropriate disclosure period depends on severity, active exploitation, the complexity of remediation, dependencies on other organisations, and the risk created by continued silence.
Proper Tools will not request indefinite silence. Where remediation takes time, the aim is to agree a reasonable disclosure plan and communicate when circumstances change.
If public communication is needed, Proper Tools will try to ensure that it describes the issue, its impact, and its correction accurately without exposing people to avoidable further risk.
Recognition
Proper Tools does not operate a bug-bounty programme and does not promise payment or other material reward.
What it does promise is a serious response, thanks, and public credit where the reporter wants it and disclosure would not create additional risk.
Changes to this page
Material changes to this page will be recorded here.
- — Substantially revised to clarify reporting, response targets, scope, good-faith research, safe harbour, coordinated disclosure, and recognition.
Last updated: