Vulnerability Disclosure Policy
Last updated: August 27, 2026
Found a vulnerability in a Fluxive system? Tell us. This document sets out what you may report, how to do it, the timelines we commit to, and the undertakings we give you in return. We take every report seriously and do not assume bad intent.
1. Scope
This policy covers systems that Fluxive itself operates:
- fluxive.be and its subdomains
- the Fluxive Housekeeping platform
- the other online services Fluxive offers in its own name
Expressly outside this policy: client infrastructure.
Fluxive manages networks, Wi-Fi installations and systems owned by its clients. Fluxive does not own them and cannot authorise you to examine or test them. A report about such a system belongs with its owner. We will point you in the right direction on request, but we cannot grant that permission on their behalf.
2. How to report
Send your report to security@fluxive.be. You will receive an automatic acknowledgement; it confirms only that your message arrived, not that it has been assessed.
Where you can, include: the system or address concerned, a description of the issue, the steps to reproduce it, and the impact as you see it. Screenshots or a short recording help. Report in Dutch, French or English.
Do not send third-party personal data where it is not needed to demonstrate the issue. If one record makes the point, send one.
3. What you can expect from us
- If your report concerns an incident affecting client data, we acknowledge it within 4 business hours.
- For all other reports, you get a substantive first response within 5 business days.
- We tell you whether we confirm the vulnerability and, if so, what we are doing about it and when.
- We keep you informed until the vulnerability is resolved.
- Fluxive is a small business. We do not promise 24/7 handling, but we do commit to answering within these timelines.
4. Responsible disclosure — 90-day window
We ask you not to make the issue public before we have had the chance to respond and fix it, within 90 days of your report. If the vulnerability is fixed sooner, you may publish as soon as we confirm that.
If we need more time, we will ask you and explain why. We do not use the window to keep a problem quiet.
5. What we ask you not to do
- No denial of service, load testing, or automated scanning that degrades the service.
- No social engineering, phishing, or approaches to staff, clients or suppliers.
- No physical access to buildings or equipment.
- Do not go further than needed to demonstrate the vulnerability: do not alter or delete data, do not download third-party data, do not retain access.
- Do not examine client systems (see section 1).
6. Legal position
If you report in good faith and stay within this policy, Fluxive will not bring civil proceedings against you over your research, and will not file a complaint against you.
We are straight about the limit of that undertaking: Fluxive can only speak for itself. Belgian criminal law on unauthorised access to computer systems (art. 550bis of the Criminal Code) is not Fluxive's to waive — the public prosecutor decides on that independently. We therefore cannot offer you criminal immunity, and anyone who promises it cannot deliver it.
Belgium also operates a national coordinated vulnerability disclosure framework, run by the Centre for Cybersecurity Belgium (CCB). This policy is Fluxive's own and does not replace it.
7. Reward
Fluxive runs no bug bounty programme and pays no reward for reports. We would rather say so up front than afterwards. What we do offer: if you want it, we will credit you by name once the vulnerability is fixed.
8. Contact
FLUXIVE
Email: security@fluxive.be
Machine-readable version: /.well-known/security.txt
Fluxive — Aman Yadav, CBE 1029.968.269