Skip to legal content
Legal & Trust Center
Trust Center Contact IK Studios ↗
Legal Center

Trust & Security

Responsible Disclosure Policy

If you have found a security vulnerability, thank you. Here is how to report it safely and what you can expect from us in return.

Owner
IK Studios
Updated
June 28, 2026
Effective
June 28, 2026
Scope
Netherlands · EU / EEA

On this page

Our commitmentHow to reportGuidelinesWhat to expect from usRewards

Back to Legal Center

Policy library

Overview

Trust CenterLegal FAQ

Privacy & Data

Privacy PolicyCookie PolicyGDPRCCPA (California)Data RetentionData DeletionPrivacy PreferencesCookie Settings

Terms & Use

Terms of ServiceLicense AgreementAcceptable UseSubscription TermsRefund Policy

Trust & Security

SecurityResponsible DisclosureSubprocessor ListThird-Party ServicesData Processing AgreementService Statussecurity.txt

Intellectual Property & Brand

Copyright PolicyCopyright NoticeTrademark PolicyBrand AssetsPress & MediaOpen Source Notices

Disclaimers & Liability

Website DisclaimerSoftware DisclaimerLimitation of Liability

Artificial Intelligence

AI Usage Policy

Accessibility

Accessibility Statement

Company

Contact & Legal InfoCommunity Guidelines

On this page

Our commitmentHow to reportGuidelinesWhat to expect from usRewards

Our commitment

We value the security community. If you make a good-faith effort to follow this policy, we will treat your research as authorised, work with you to understand and resolve the issue quickly, and not pursue legal action against you for that research.

How to report

Email support@ikstudios.nl with “Security” in the subject. Helpful reports include:

  • A clear description of the issue and its potential impact.
  • Steps to reproduce, including affected URLs, parameters, or product surfaces.
  • Any proof-of-concept, logs, or screenshots that help us verify it.
  • How you would like to be credited, if at all.

Guidelines

To keep everyone safe, please:

  • Only test against your own accounts and data — never access, modify, or delete other people's data.
  • Avoid denial-of-service, spam, social engineering, and physical attacks.
  • Do not run automated scanning that degrades our services.
  • Give us a reasonable opportunity to fix the issue before public disclosure.

What to expect from us

We aim to acknowledge good-faith reports, keep you updated as we investigate, fix confirmed issues as quickly as we reasonably can, and credit you if you would like. We will be honest about timelines.

Rewards

No paid bug bounty (yet)

We do not currently operate a paid bug-bounty programme. We greatly appreciate responsible reports and will offer public credit and our genuine thanks. If we introduce rewards in future, we will update this policy.

Contact & notices

Questions about these documents, your privacy rights, a security report, or a business agreement — we read every message and route it to the right person.

General, privacy & security
support@ikstudios.nl
Business & billing
sales@ikstudios.nl
Product feedback
feedback@ikstudios.nl
Full contact page
Contact & Legal Information
Legal CenterPrivacyTermsCookiesSecurityTrust CenterContactIK StudiosVault One

IK Studios policies are written to be read — plain language first, with the detail behind it. We keep them aligned to what we actually build.

Last updated June 28, 2026. Questions: support@ikstudios.nl. These documents apply to IK Studios and its websites; product-specific terms for Vault One live in the Vault One Trust Center.

© 2026 IK Studios. An independent software studio.