Rooted
Back to bounty board
AA
Vulnerability disclosure program

Aalten

aalten.nl / public reporting path

Partial70 signal

Municipal digital services, public forms, authentication flows and exposed APIs are the practical focus. Avoid service disruption, citizen data access, phishing and physical testing.

Safe harbor
There is non-hostile language, but confirm the scope before you test.
Disclosure
The timeline may be defined by the policy, or not stated at all.
Intake
https://www.aalten.nl/digitale-kwetsbaarheid-melden
Scope rules

In scope

  • *.aalten.nl
  • aalten.nl

This programme publishes no asset list, so everything under the primary domain is treated as in scope. Read the policy before you touch anything.

Out of scope

  • Social engineering against staff or customers
  • Physical intrusion or on-site testing
  • Denial of service, load testing or resource exhaustion
  • Credential brute force or password spraying
  • Leaving persistence, backdoors or planted accounts
  • Accessing data belonging to real users
  • Unthrottled automated scanning
Scope rules

What Rooted expects in a valid report

In scope

Owned public web assets, auth/session logic, exposed APIs, account boundaries, sensitive data exposure and clear misconfiguration with reproducible impact.

Out of scope

Social engineering, physical testing, spam, denial of service, brute force, persistence, malware, extortion language and access to data that is not yours.

Report quality

Include affected asset, severity, exact steps, observed impact and safe evidence. We score reports faster when the reproduction is clean.

Verification

Rooted reviews the submission and may coordinate with the listed program. Points are released only after the finding is confirmed.