Kwetsbaarheid melden
Laatste update: 1 augustus 2026
Finibase verwerkt financiële en operationele data van accountancy- en auditkantoren. Denk je een beveiligingsprobleem gevonden te hebben in het platform of op deze website, dan horen we dat graag rechtstreeks van jou, vóór iemand anders het vindt. Stuur je melding naar security@finibase.com.
Hoe het verloopt
Stuur je melding naar security@finibase.com
Beschrijf wat je gevonden hebt, op welke URL of welk endpoint, en welke impact het volgens jou heeft. Voeg de stappen toe waarmee wij het probleem zelf kunnen reproduceren, plus screenshots of een proof of concept als je die hebt.
Je krijgt binnen 5 werkdagen een bevestiging
We laten weten dat je melding aangekomen is en wie ze opvolgt. Daarna beoordelen we of het probleem reproduceerbaar is en hoe zwaar we de impact inschatten.
We lossen op volgens ernst
Problemen met hoge impact krijgen voorrang op ons lopende werk. Minder ernstige bevindingen volgen de normale planning. We koppelen terug zodra de oplossing live staat.
We documenteren de melding intern
Elke geldige melding krijgt een onderzoeksdossier, net zoals kwetsbaarheden die we zelf vinden. Was er klantdata bij betrokken, dan volgen we onze meldingsprocedure richting de betrokken kantoren en de bevoegde autoriteit.
Scope
In scope
- app.finibase.com, het Finibase-platform
- finibase.com, deze website
- De publieke API-endpoints van het platform
- De Finibase-connector voor AI-assistenten
Buiten scope
Onderstaande bevindingen nemen we niet in behandeling. Ze komen bijna altijd uit een geautomatiseerde scan en zeggen op zichzelf niets over de veiligheid van de dienst.
- Diensten van derden die wij afnemen. Meld die rechtstreeks bij de betrokken leverancier.
- Ontbrekende security headers zonder aantoonbaar misbruik
- SPF-, DKIM- of DMARC-records op domeinen die geen e-mail versturen
- Clickjacking op pagina's zonder acties die iets wijzigen
- Versienummers of banners zonder werkende proof of concept
- Self-XSS en problemen die de melder alleen bij zichzelf kan uitlokken
- Uitvoer van SSL/TLS-configuratiescanners zonder concrete impact
- Rate limiting op endpoints die geen gevoelige data raken
Spelregels
Onderzoek naar onze beveiliging is welkom zolang het niemand schaadt. Concreet vragen we het volgende.
- Raak geen data aan van een account dat niet van jou is. De gegevens op ons platform zijn vertrouwelijke gegevens van accountancy- en auditkantoren en van hun klanten.
- Geen denial of service, load tests of geautomatiseerd scannen dat de dienst verstoort.
- Geen social engineering van onze medewerkers, klanten of leveranciers, en geen fysieke toegangspogingen.
- Behoud geen toegang nadat je hebt aangetoond dat het probleem bestaat, en installeer niets.
- Publiceer niets voor we de kans hadden om het op te lossen.
Safe harbour
Houd je je aan bovenstaande spelregels, dan beschouwen we jouw onderzoek als uitgevoerd met onze toestemming en ondernemen we geen juridische stappen tegen jou.
Geen betaald bounty-programma
Finibase betaalt geen vergoedingen voor meldingen. We nemen elke geldige melding wel ernstig en behandelen ze volgens de procedure hierboven. Wil je vermeld worden nadat we het probleem opgelost hebben, laat dat dan weten in je melding, dan doen we dat graag.
Machine-leesbare contactgegevens: /.well-known/security.txt (RFC 9116). Voor de maatregelen die we zelf nemen, zie het trust center.
Reporting a vulnerability
Last updated: 1 August 2026
Finibase processes financial and operational data for accounting and audit firms. If you think you found a security issue in the platform or on this website, we would rather hear it from you directly, before someone else finds it. Send your report to security@finibase.com.
How it works
Send your report to security@finibase.com
Describe what you found, on which URL or endpoint, and the impact you believe it has. Include the steps that let us reproduce it ourselves, plus screenshots or a proof of concept if you have one.
You get an acknowledgement within 5 business days
We confirm that your report arrived and who is handling it. After that we assess whether the issue reproduces and how severe we judge the impact to be.
We fix in order of severity
High-impact issues take priority over our planned work. Less severe findings follow the normal schedule. We report back to you once the fix is live.
We document the report internally
Every valid report gets an investigation record, the same as vulnerabilities we find ourselves. If customer data was involved, we follow our notification procedure towards the affected firms and the supervisory authority.
Scope
In scope
- app.finibase.com, the Finibase platform
- finibase.com, this website
- The platform's public API endpoints
- The Finibase connector for AI assistants
Out of scope
We do not take the findings below into consideration. They almost always come out of an automated scan and say nothing on their own about the security of the service.
- Third-party services we use. Report those to the vendor directly.
- Missing security headers without a demonstrated exploit
- SPF, DKIM or DMARC records on non-sending domains
- Clickjacking on pages without state-changing actions
- Version numbers or banners without a working proof of concept
- Self-XSS and issues a reporter can only trigger against themselves
- SSL/TLS configuration scanner output without concrete impact
- Rate limiting on endpoints that touch no sensitive data
Rules
Research into our security is welcome as long as it harms no one. Concretely, we ask the following.
- Do not access, modify or exfiltrate data belonging to any account other than your own. The data on our platform is confidential information of accounting and audit firms and of their clients.
- No denial of service, load testing, or automated scanning that degrades the service.
- No social engineering of our employees, customers or vendors, and no physical access attempts.
- Do not maintain access after demonstrating the issue, and do not install anything.
- Give us reasonable time to fix an issue before disclosing it publicly.
Safe harbour
If you follow the rules above, we consider your research to be authorised by us and we will not pursue legal action against you.
No paid bounty program
Finibase does not pay rewards for reports. We do take every valid report seriously and handle it according to the process above. If you would like to be credited once we have fixed the issue, say so in your report and we are happy to do that.
Machine-readable contact details: /.well-known/security.txt (RFC 9116). For the measures we take ourselves, see the trust center.