Responsible Disclosure

At Relationship Management Consultants NV (RMC), we consider the security of our systems, services, and customer data a top priority. Despite our continuous efforts to maintain a secure environment, vulnerabilities may still exist.

If you discover a security vulnerability in one of our public-facing systems, we encourage you to report it to us responsibly. We are committed to investigating legitimate reports and resolving validated vulnerabilities as efficiently as possible.

Scope

This Responsible Disclosure Policy applies to the following public websites:

Systems and services operated by third parties are outside the scope of this policy unless explicitly stated otherwise.

How to Report a Vulnerability

Please report vulnerabilities as soon as possible by:

To help us assess and remediate the issue quickly, please include:

  • A description of the vulnerability
  • The affected URL or system
  • Steps to reproduce the issue
  • Any supporting screenshots or evidence
  • Your contact details

Our Commitment

If you act in good faith and comply with this policy, RMC will:

  • Acknowledge receipt of your report as soon as reasonably possible.
  • Investigate the reported vulnerability.
  • Keep you informed about the progress of our assessment.
  • Work to develop and deploy an appropriate remediation.
  • Coordinate any public disclosure where appropriate.

What We Ask From Security Researchers

To protect our customers, employees, and business operations, we ask that you:

  • Act in good faith and with the sole purpose of improving security.
  • Avoid actions that could negatively impact confidentiality, integrity, or availability.
  • Access only the minimum information required to demonstrate the vulnerability.
  • Stop testing once sufficient evidence has been obtained.
  • Keep vulnerability details confidential until remediation has been completed.
  • Immediately halt testing and contact us if you encounter personal, confidential, or sensitive information.

Activities Not Permitted

The following activities are explicitly prohibited:

  • Denial-of-Service (DoS/DDoS) attacks
  • Social engineering or phishing
  • Malware installation
  • Password attacks, credential theft, or brute-force testing
  • Data modification or deletion
  • Access to information that is not required to demonstrate the vulnerability
  • Interception of communications
  • Any activity that may disrupt services or impact other users

Safe Harbour

RMC will not initiate legal action against researchers who:

  • Act in good faith;
  • Follow this Responsible Disclosure Policy;
  • Respect applicable laws and regulations; and
  • Cooperate responsibly throughout the disclosure process.

Full Coordinated Vulnerability Disclosure Policy

This webpage provides a summary of our Responsible Disclosure process. The complete Coordinated Vulnerability Disclosure Policy (CVDP), including detailed reporting requirements, legal considerations, and procedural information, can be obtained upon.

Responsible Disclosure Contact
📧 info@rmconsulting.be
🌐 https://rmconsulting.be/contact/

Last updated: September 2026