Security contact
Report a security concern
Please report suspected vulnerabilities, accidental exposure, authentication problems, or access-control failures privately to peter.tamas@wur.nl.
Do not include passwords, credentials, session cookies, identity tokens, private manuscripts, source documents, or another reviewer’s material in the initial report.
Helpful information
Where safe, include:
- the affected public URL or application area;
- the approximate date and time;
- the behaviour observed;
- minimal reproduction steps;
- the apparent security or privacy impact;
- the browser or client used;
- whether the issue concerns public information or the restricted demonstrator.
Do not test beyond what is required to identify and report the suspected problem.
Research boundary
A security report does not authorise additional testing.
Without prior written permission, do not perform:
- automated vulnerability scanning;
- denial-of-service or load testing;
- persistence;
- privilege escalation;
- social engineering;
- credential testing;
- data exfiltration;
- access to another user’s workspace;
- access to private manuscripts or review records;
- probing of non-public services;
- destructive testing.
Stop testing if private or sensitive information becomes visible and report the issue through the private contact route.
Current status
The current OS-ERIN service operator is Biometris, Wageningen University & Research.
The private application is exposed only through the reviewed HTTPS and SURF SRAM boundary for the current operator-validation account.
This bounded sign-in route does not establish:
- production security;
- completed penetration testing;
- a complete institutional incident process;
- final vulnerability-disclosure policy;
- permission for unrestricted external testing;
- readiness to invite additional users.