At SNC, we consider the security of our ICT systems and our websites of utmost importance. We therefore strive for the highest possible level of security. Despite the great care we take with respect to ICT security, weaknesses can still remain. We ask you not to abuse a vulnerability, but to report the issue to us so that we can take the necessary measures.
Have you found a vulnerability in our websites or in one of our other (online) systems? Then please report your findings to us as soon as possible. Do that before you announce the 'leak' to the outside world, so we can solve it as quickly as possible.
We would like to work together to better protect our systems and to remedy a vulnerability as soon as possible. Our responsible disclosure policy is however not an invitation to actively scan our business network to discover weak points.
If you discover a vulnerability, do not take advantage of it by, for example:
Have you reported a weak spot in one of our ICT systems or websites? Then we will treat your report as follows:
We will resolve a reported security problem as quickly as possible, but always within 60 days. Together with you (the reporter of the issue), we will determine whether and how we report about the problem. If we communicate about an issue, we will only do that after we will have solved it.
SNC may revise the policy with respect to the responsible disclosure if there is reason to do so. The current policy is always on this page.
We are SNC, a world top 20 leader in Testing, Inspection and Certification (TIC). With our certification, inspection, testing, training and consultancy services, we create trust in our customers' products, services, processes, (management) systems and employees.