Our commitment
We value the security community. If you make a good-faith effort to follow this policy, we will treat your research as authorised, work with you to understand and resolve the issue quickly, and not pursue legal action against you for that research.
How to report
Email support@ikstudios.nl with “Security” in the subject. Helpful reports include:
- A clear description of the issue and its potential impact.
- Steps to reproduce, including affected URLs, parameters, or product surfaces.
- Any proof-of-concept, logs, or screenshots that help us verify it.
- How you would like to be credited, if at all.
Guidelines
To keep everyone safe, please:
- Only test against your own accounts and data — never access, modify, or delete other people's data.
- Avoid denial-of-service, spam, social engineering, and physical attacks.
- Do not run automated scanning that degrades our services.
- Give us a reasonable opportunity to fix the issue before public disclosure.
What to expect from us
We aim to acknowledge good-faith reports, keep you updated as we investigate, fix confirmed issues as quickly as we reasonably can, and credit you if you would like. We will be honest about timelines.
Rewards
No paid bug bounty (yet)
We do not currently operate a paid bug-bounty programme. We greatly appreciate responsible reports and will offer public credit and our genuine thanks. If we introduce rewards in future, we will update this policy.