Vulnerability Disclosure Policy
Last updated: March 1, 2026
1. Introduction
Drimble ("Liplyn IG") takes the security of its systems, platforms, and data seriously. We value the efforts of security researchers and the broader community in helping to protect our systems and users. This policy outlines how to report vulnerabilities to us in a responsible manner.
2. Scope
This policy applies to all digital assets owned or operated by Liplyn IG, including but not limited to:
- liplyn.com
- drimble.com
- drimble.nl
- datafloq.com
- vacant.nl
- bouwvacatures.nl
- techniekvacaturebank.nl
- SpotOnTheUSA Network websites
- All other domains and subdomains operated by Liplyn IG
3. Reporting Guidelines
If you have discovered a security vulnerability, we ask that you:
- Email your findings to sales@drimble.com with a detailed description of the vulnerability.
- Provide sufficient information to reproduce the vulnerability so we can verify and resolve the issue quickly.
- Do not publicly disclose the vulnerability before we have had a reasonable period to address the issue.
- Do not exploit the vulnerability beyond what is necessary for verification, modify or delete third-party data, or disrupt the availability of systems.
4. What to Expect
- We will acknowledge receipt of your report within 3 business days.
- We will keep you informed of the progress toward a resolution.
- We aim to resolve all vulnerabilities within a reasonable timeframe.
- We will not take legal action against researchers who comply with this policy.
5. Out of Scope
The following are out of scope for this policy:
- Social engineering attacks (e.g., phishing)
- Denial of Service (DoS/DDoS) attacks
- Spamming or brute force attacks
- Vulnerabilities in third-party software not managed by Liplyn IG
- Findings from automated scanners without demonstrated impact
6. Safe Harbor
Liplyn IG considers activities conducted consistent with this policy to constitute authorized conduct. We will not pursue civil or criminal action, or file a complaint with law enforcement, against individuals who report vulnerabilities in good faith and in accordance with this policy.
7. Contact
Security vulnerabilities can be reported to:
DrimbleMarathon 9a
1213 PE Hilversum
The Netherlands
sales@drimble.com
