Vulnerability disclosure policy
How to report a security problem in WebCrew safely, what we do with it, and what we promise you in return.
Published 1.0 · 2026-10-01
Effective date: 1 October 2026
This policy is published by JKC Software B.V., High Tech Campus 32, 5656 AE Eindhoven, the Netherlands, KvK 42082783. It is the Vulnerability Disclosure Policy that the Data Processing Agreement (Annex A) and the Website Terms (clause 7) refer to. It follows the Dutch guideline for coordinated vulnerability disclosure published by the NCSC.
1. What is in scope
- The public website webcrew.ai and its subdomains.
- The product at app.webcrew.ai, including its API and the hosted MCP server.
- The WebCrew Connector plugin, in the version we distribute.
Out of scope: the WordPress sites our customers connect, third-party plugins and themes (report those to their vendor), and the infrastructure of our providers. If a problem in a third-party component affects WebCrew itself, it is in scope.
2. How to report
2.1 Send your report to security@webcrew.ai. If that address does not answer, use security@jkc.media. Reports in English or Dutch are both fine.
2.2 Include what we need to reproduce it: the affected URL or component, the steps, what you expected and what happened, and the impact you think it has. A proof of concept helps; keep it minimal.
2.3 Leave a way to reach you. You may report anonymously, but then we cannot keep you informed or thank you.
3. What we ask of you
- Report the problem to us as soon as possible after you find it, and do not share it with others until it is fixed.
- Do no more than you need to show the problem. Do not copy, change or delete data, and do not access data of other customers. If you come across personal data, stop and tell us.
- Do not test against connected customer sites, and do not use your access to move further into our systems.
- No denial-of-service, no high-volume automated scanning, no social engineering, phishing or physical access attempts.
- Do not place backdoors or malware, not even to demonstrate the problem.
- Delete any data you obtained once the problem is reported.
4. What we promise you
4.1 A person reads your report the same working day and confirms receipt within two working days, with a first assessment within five working days.
4.2 We keep you informed while we work on a fix and tell you when it is resolved. Critical and high-severity issues are fixed as a priority; we aim to resolve every confirmed issue within 90 days.
4.3 If you have acted within this policy, we will not take legal action against you and will not report you to the police for the research covered by your report. This does not apply where there are clear criminal intentions or where the rules above are knowingly broken.
4.4 We treat your report and your details confidentially and do not share your personal data with third parties without your permission, unless the law requires it.
4.5 With your permission, we name you as the finder when we publish about the issue. We do not run a paid bug bounty; a reward for a valuable report is at our discretion.
5. Coordinated publication
We would rather publish together. Once a fix is live, we agree with you when and how the problem is made public. Where a fix takes longer than 90 days, we explain why and agree a new date with you.
6. What we generally do not treat as a vulnerability
- Missing security headers or cookie flags without a demonstrated impact.
- SPF, DKIM or DMARC configuration findings.
- Clickjacking on pages without sensitive actions, self-XSS, and issues that require a compromised device.
- Rate limiting on endpoints that are not related to authentication.
- Version disclosure or banner information on its own.
Not sure? Report it anyway. We would rather hear it from you than read it elsewhere.
7. Changes
We may change this policy; the version in force is the one published here, with the date at the top.