SECURITY
Security at The Pineapple Club
Responsible Disclosure Policy
The Pineapple Club’s Responsible Disclosure Policy explains how security researchers can safely report vulnerabilities affecting our website and member platform. Responsible reporting helps us protect our members, their privacy, and the security of our community.
Scope of this policy
This Responsible Disclosure Policy covers security vulnerabilities affecting the following production domains:
- pineappleclub.nl The Pineapple Club marketing website
- app.pineappleclub.nl The Pineapple Club member platform and production environment
Out of scope
- Test and staging environments This includes app.staging.pineappleclub.nl and other non-production environments. These environments are not intended for public access and contain no real member data. Reports will only be accepted when the issue can also be reproduced in production.
- Third-party applications and integrations This includes payment providers, API integrations, embedded widgets, linked applications, and other external services. Vulnerabilities should be reported directly to the relevant third party.
- Social engineering Phishing, vishing, impersonation, or other attacks against our staff or members.
- Physical attacks Attacks against offices, employees, devices, or infrastructure.
- Denial-of-service attacks DoS, DDoS, stress testing, or other attacks affecting the availability of our services.
- Spam or content injection Reports without a clearly demonstrated security impact.
- Third-party services we embed or link to Please report these vulnerabilities to the organization responsible for the affected service.
Ground rules for security research
Please follow these ground rules when investigating or reporting a potential security vulnerability:
- We do not provide test accounts to researchers. Only test using an account you legitimately own.
- If you believe your actions could cause damage, data loss, disruption, or downtime, stop immediately and report the issue before continuing.
- Never access, modify, copy, download, or delete data belonging to other members.
- Do not use automated scanners or testing tools that could disrupt the service without prior coordination with us.
- Do not publicly disclose the vulnerability before we have resolved it. We follow a coordinated disclosure process.
How to report a security vulnerability
If you have discovered a potential security vulnerability affecting The Pineapple Club, please send your report to:
Report a security vulnerabilityAlternatively, email [email protected] .
Please include the following information in your report:
- A clear description of the vulnerability and its potential impact
- Steps to reproduce the issue, including a proof of concept where relevant
- No destructive payloads or unnecessary access to personal data
- The affected URL, page, endpoint, or domain
- Your contact details for follow-up questions
What you can expect from us
After receiving a responsible disclosure report, we will review the information and keep you informed about our progress.
Business days
We will acknowledge receipt of your report.
Business days
We aim to provide an initial assessment.
Progress updates
We will keep you informed until the issue has been resolved.
Recognition
With your consent, we may recognize your contribution in our Security Hall of Fame after the vulnerability has been resolved.
Safe harbor
If you comply with this Responsible Disclosure Policy, we will not pursue legal action against your security research. We consider research conducted within the scope and ground rules described above to be authorized.
Supporting the security of our community
Responsible security research helps us maintain a safe and trusted environment for our members. Researchers whose valid reports help us improve our security may, with their consent, be recognized in our Security Hall of Fame.