Code24 · Vulnerability Disclosure

Code24 Vulnerability Disclosure

Vulnerability disclosure

Code24 publishes a vulnerability disclosure policy for reporting security issues. A dedicated security contact is published.

CompanyHealthcareElectronic Health RecordsopenEHRFHIRMedMijInteroperabilityMental HealthNetherlandsHealth Data
Program:

Disclosure Policy

Security Contact

Contact
emailsecurityofficer@code24.nl
Contact
pgptrue
Contact
pgp_algorithmEdDSA (Ed25519), created 2022-10-24
Contact
pgp_fingerprint808463365234FAC600E5F3D65FF8001446902779
Contact
pgp_key_published_inlinetrue
Contact
pgp_key_uidSecurityofficer Code24
Contact
pgp_noteAn ASCII-armoured public key block is published inline on the disclosure page. The fingerprint above was computed here (SHA-1 over the v4 public-key packet) from that published block on 2026-09-02; it is recorded for identification only and is not a substitute for verifying the key out of band. The key block itself is not copied into this repo.

Source

Vulnerability Disclosure

code24-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-02'
method: searched
source: https://www.code24.nl/kwetsbaarheid-melden
program:
  name: Coordinated Vulnerability Disclosure (Kwetsbaarheid melden)
  published: true
  url: https://www.code24.nl/kwetsbaarheid-melden
  language: nl
  last_updated: '2023-01'
  http_status: 200
  bug_bounty: false
  platform: null
  note: >-
    A self-hosted CVD policy page, not a bug-bounty programme and not an RFC 9116 security.txt.
    /.well-known/security.txt returns 404 on every CODE24 host; a /securitytxt page exists on the
    site but its body contains only the words "security.txt".
contact:
  email: securityofficer@code24.nl
  pgp: true
  pgp_key_published_inline: true
  pgp_key_uid: Securityofficer Code24 <securityofficer@code24.nl>
  pgp_fingerprint: 808463365234FAC600E5F3D65FF8001446902779
  pgp_algorithm: EdDSA (Ed25519), created 2022-10-24
  pgp_note: >-
    An ASCII-armoured public key block is published inline on the disclosure page. The fingerprint
    above was computed here (SHA-1 over the v4 public-key packet) from that published block on
    2026-09-02; it is recorded for identification only and is not a substitute for verifying the
    key out of band. The key block itself is not copied into this repo.
commitments:
- Initial response with an assessment and an expected fix date within three days.
- No legal action against reporters who follow the stated conditions.
- Reports handled confidentially; personal data not shared with third parties without consent.
- Reporter kept informed of remediation progress.
- Public credit to the reporter by name on request.
reporter_conditions:
- Do not exploit the finding beyond what is needed to demonstrate it; do not download excess data or read, delete or modify third-party data.
- Do not disclose to others until fixed, and erase any confidential data obtained.
- No physical attacks, social engineering, DDoS, spam, or attacks on third-party applications.
- Provide enough information to reproduce (typically the IP address or URL plus a description).
scope:
  in_scope:
  - Domains ending in code24.nl
  - CODE24 websites and software
  out_of_scope:
  - Any system on a domain other than code24.nl
  - SPF/DMARC record findings
  - (D)DoS and rate-limiting of calls
  - Self-XSS
  - Error messages without sensitive data
  - Reports that merely disclose which software CODE24 uses
  - Complaints, website-availability reports, phishing e-mail reports, and fraud reports

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/code24-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.