Customer portal System status Developers Contact Search
Legal

Coordinated vulnerability disclosure policy

Scope, safe harbour, timelines and how to report a security issue to Terravek.

Report to security@terravek.com. We acknowledge within 72 hours. You do not need to sign anything first, and we will not ask you to. We do not run a paid bounty.

Our commitments to you

  • Acknowledgement within 72 hours. Our median in 2025 was 11 hours.
  • An assessment within ten working days, saying whether we agree it is a vulnerability, what severity we have assigned, and why.
  • Progress updates at least every fourteen days until it is closed. If a fix is slow — the slowest in 2025 was 94 days, on a third-party dependency — we tell you that rather than going quiet.
  • Credit in our hall of thanks, with your consent, under whatever name or handle you prefer.
  • A reply written by an engineer, not by a lawyer. If we disagree with you we will explain why, and we have changed our mind when a reporter pushed back.
  • Safe harbour — see below.

Safe harbour

If you make a good-faith effort to comply with this policy during your research, Terravek will not initiate or support legal action against you in connection with it, and will consider your research authorised under the Dutch Computer Crime Act and equivalent legislation. If a third party brings action against you for activity conducted under this policy, we will make that authorisation clear.

In scope

  • terravek.com and its subdomains
  • api.terravek.com — the ATLAS API
  • portal.terravek.com, partners.terravek.com
  • identity.terravek.com
  • The ORBIS Viewer web application
  • Terravek mobile applications (FIELDKIT companion app)
  • FIELDKIT device firmware
  • Terravek open-source repositories at github.com/terravek

Out of scope

  • Third-party services on our domains that we do not control (our status page and ticketing are hosted services — report those to the vendor, and tell us too)
  • Missing security headers, cookie flags or TLS configuration without a demonstrated impact. We will read it, but it is unlikely to be treated as a finding.
  • Rate limiting on unauthenticated endpoints, absent a demonstrated amplification
  • Reports generated wholly by an automated scanner with no validation
  • Social engineering of Terravek staff, customers or suppliers
  • Physical attacks against our offices or the Svalgrund site
  • Denial of service, volumetric testing, or anything that degrades service for others

What we ask of you

  • Give us reasonable time to fix it before publishing — we suggest 90 days, and will discuss it if you have a reason for a different timeline.
  • Do not access, modify or delete data that is not yours. If you encounter customer data, stop and tell us.
  • Use test accounts where you can. Ask us for one — we will provide it.
  • One issue per report, with enough detail to reproduce.
  • Do not use a finding to extract payment. We do not pay bounties, and a report conditioned on payment will be treated as such.

How reports are handled

Triage by Laura Peeters (Security Engineer, Application Security), escalated as needed to Riina Tamm (Head of Security Operations) and Ingrid Halvorsen (Chief Information Security Officer). Severity is assigned using CVSS 4.0 with a documented environmental adjustment.

Last year's numbers

31 reports in 2025: 8 valid and fixed, 3 valid and risk-accepted with the reasoning shared back to the reporter, 11 out of scope, 9 duplicates. Median first response 11 hours; median time to fix 19 days. The full write-up.

Machine-readable

This policy is referenced from /.well-known/security.txt in accordance with RFC 9116, including our PGP key fingerprint and preferred languages.

Last revised 2 April 2026. Questions: legal@terravek.com