NEVERYTIME

Finding solutions for problems yet to be found.

Back to NEVERYTIME ↗

Coordinated disclosure · Version 2026.09

Found a weakness? Tell us without making it worse.

We welcome good-faith reports about suspected vulnerabilities in Neverytime-owned systems. This policy creates a careful route for verification and repair; it is not permission to test clients, providers or unrelated third parties.

Start a report · bart@neverytime.nl ↗
ScopeRules of careReportResponseDisclosureSafe harbour

01

What is in scope

Only internet-facing systems and applications demonstrably owned and operated by Neverytime B.V. are in scope. Customer environments, third-party platforms, hosting-provider infrastructure, employee accounts, personal devices and services merely linked from our site are out of scope unless Neverytime gives you specific written authorisation for the named asset and test.

If ownership is unclear, stop and ask. A report based on observation is welcome; uncertainty is not permission to probe.

02

Rules of care

Use the least intrusive method and only the minimum proof needed to describe the issue. Stop immediately if you encounter personal data, confidential information, credentials or signs of service impact. Do not copy, change, delete, retain or disclose data you do not own.

Not permitted

Denial of service; traffic flooding; social engineering; phishing; physical access; malware; persistence; lateral movement; password spraying or brute force; automated scanning that degrades service; accessing another person’s account; exfiltration; or testing any customer or third-party asset. Do not exploit further than needed to establish a plausible finding.

03

How to report

Email bart@neverytime.nl with [CVD] in the subject. Include the affected URL or asset, the date and time, a clear description, the minimum steps needed to reproduce it, likely impact and your preferred contact details. Remove unrelated personal data and redact secrets.

Do not send live credentials, database extracts or sensitive evidence by ordinary email. First provide a non-sensitive summary; we will agree a protected transfer route if richer evidence is necessary.

04

What you can expect

We aim to acknowledge a credible report within three business days and provide an initial status or request for clarification within ten business days. These are targets, not guaranteed remediation deadlines. Priority and timing depend on reproducibility, impact, affected dependencies and the safety of a fix.

We will limit report access, investigate proportionately and keep you informed when useful. Neverytime does not operate a standing bug-bounty programme, and no payment or reward is promised unless agreed in writing before additional work is performed.

05

Coordinated publication

Give us a reasonable opportunity to investigate and remediate before publication. Do not disclose the vulnerability, affected data or exploit details publicly or to others until we confirm a remedy or both sides agree a disclosure date and content. We will not use coordination to suppress legitimate research indefinitely; timing should reflect actual risk and remediation progress.

06

Good faith and legal boundaries

When you act in good faith, stay within this policy, avoid harm and cooperate on remediation, Neverytime’s intention is not to pursue a legal claim against you for that authorised research. If your work falls outside this policy, contact us before continuing so written permission can be considered.

This statement cannot authorise conduct on systems we do not own, bind clients, providers, law-enforcement bodies or other third parties, or protect unlawful conduct. You remain responsible for complying with applicable law.

Registered business

Neverytime B.V.
Cornelis Jolstraat 20 A
2584 ER ’s-Gravenhage
The Netherlands

Direct

+31 6 2738 1295bart@neverytime.nl

Legal identifiers

KVK 84008059

VAT NL863062362B02

Statutory seat: Amsterdam

Read

Privacy & cookiesLegal & termsReport a vulnerability
© 2026 Neverytime B.V.Independent minds. Collective futures.