Disclosure policy
At RingRing, the security of our systems is of utmost importance. Despite our efforts to safeguard these systems, vulnerabilities may still exist. If you discover a vulnerability or security flaw—whether in our physical or digital systems—please report it to us promptly, so we can take swift action. We welcome your cooperation in helping to protect our systems, customers, and ecosystem more effectively.
1. Introduction
This policy applies to all stakeholders of RingRing and to any of its services and platforms.
2. Audience
We seek the cooperation of various audiences within the scope of this policy, including, but not limited to:
- Website visitors
- Visitors to RingRing premises
- Employees and staff
- Customers
- Contractors and partners
- Prospects
- …
3. Protocol
What We Ask You to Do
If you have discovered a vulnerability, please:
- Provide sufficient information to reproduce the issue so that we can resolve it as quickly as possible. Usually, the IP address or URL of the affected system and a description of the vulnerability will suffice, though more complex issues may require additional details.
- Send your report to security@ringring.be.
What We Ask You NOT to Do
When a vulnerability is discovered, we request that you refrain from:
- Exploiting the vulnerability by, for example, downloading more data than necessary to demonstrate the issue or accessing, deleting, or modifying third-party data.
- Sharing the vulnerability with others before it has been resolved. Also, please erase any confidential information obtained through the vulnerability once it has been addressed.
- Engaging in attacks related to physical security, social engineering, distributed denial-of-service (DDoS), spam, or third-party applications, as well as any actions that could damage or disrupt our systems.
Legal Considerations
Please note that a legal framework must be followed (refer to the legal section below). Unauthorized access to our systems can and will be prosecuted to the fullest extent of the law if regulatory protocols are violated.
What you can expect from us
- We will respond to your report as soon as possible, within a maximum of 5 business days, providing an initial assessment and an estimated timeline for resolution.
- If you comply with the terms outlined above and adhere to applicable cyber laws, we will not pursue legal action against you concerning your report.
- We will treat your report confidentially and will not share your personal information with third parties without your permission, unless required by law.
- If desired, we will keep you informed about the progress of resolving the issue.
- If you wish, we will acknowledge you as the discoverer when notifying others of the reported vulnerability.
Public disclosure of vulnerabilities
Only RingRing has the authority to make any public or official announcements regarding discovered vulnerabilities. No publication is allowed without prior agreement and approval from RingRing.
4. Courtesy
This responsible disclosure policy is based on the open-source project licensed under Creative Commons v3: Responsible Disclosure.
5. Legal reference
Please be aware that reporting vulnerabilities is subject to legal regulations.
Since RingRing is headquartered in Belgium, Belgian law on vulnerability disclosure applies.
In summary (from the CCB website):
- You must limit your actions strictly to what is necessary to report the vulnerability. Avoid actions beyond what is required to verify the vulnerability.
- You must act without malicious intent or intent to harm.
- As soon as you discover a potential vulnerability, you must notify the organization responsible for the system or control affected, no later than the time of reporting to the national CSIRT.
- You must report the vulnerability as soon as possible to RingRing, in writing and following the procedures.
- You must not publicly disclose information about the vulnerability without the approval of the national CSIRT (CCB).
More information: CCB – Vulnerability Reporting
6. General company info
Website: https://www.ringring.be/
Contact: https://www.ringring.be/contact/
VAT: BE0445262068 (Belgium)
The Ring Ring Company
Culliganlaan 2/F B9
1831 Diegem
Belgium
Phone: +32 2 334 23 45
Email: info@ringring.be















