Chargement...
Chargement...
Last updated: 2 October 2026
The security of our services and products is at the heart of what we do. If you believe you have found a vulnerability, please report it to us responsibly, following the rules below, so that we can fix it before any public disclosure.
Varden Security does not run a financial reward programme (bug bounty). With your consent, we are happy to acknowledge your contribution once the vulnerability has been fixed.
This policy covers:
Out of scope: our customers' systems, our suppliers' services (hosting, payment, email), as well as denial-of-service attacks, social engineering, physical testing and unsolicited messages.
Write to security@varden.io and include:
You may write in French, English or Dutch. If you wish to send us encrypted information, ask us for a key through the same channel.
For your research to remain in good faith, we ask you:
In Belgium, good-faith vulnerability reporting is governed by law. Its conditions are set out by the Centre for Cybersecurity Belgium (CCB), to which the report may also be sent.
Where a vulnerability affects a product we place on the market, we comply with the reporting obligations of the EU Cyber Resilience Act (CRA), including towards ENISA and the competent CSIRT.
Any personal data you send us in a report is used solely to handle it, in accordance with our privacy policy.
Report a vulnerability
security@varden.io