Responsible Disclosure

The responsible disclosure policy applies to the following systems:

  • www.fundaments.nl
  • portal.fundaments.nl
  • status.fundaments.nl
  • ots.fundaments.nl

We would like to collaborate with you to enhance the safeguarding of our customers and systems.

We ask you

  • Kindly submit your findins via email to sec@fundaments.nl or contact us 0884227227;
  • Kindly refrain from exploiting the identified issue, including excessive data downloading to demonstrate the vulnerability or accessing, modifying or deleting third party data;
  • Kindly refrain from disclosing the issue to others until it has been resolved, and ensure the prompt deletion of any confidential data obtained through the vulnerability immediately after it has been addressed;
  • Kindly refrain from utilizing attacks on physical security, engaging in social engineering, participating in distributed denial of service activities, sending spam, or exploiting third party applications;
  • Kindly provide adequate information to replicate the problem for a prompt resolution; In the majority of the cases, providing the IP address or URL of the affected system along with a detailed description of the vulnerability is sufficient. However, additional information may be required for more complex vulnerabilities.

We promise

  • We respond to you report within 3 business days, including our assessment of the issue and an estimated date for its resolution;
  • Should you comply with the above conditions, we wil not take any legal action against you regarding the reported issue;
  • We handle your report with utmost confidentiality and will not disclose your personal information to third parties without your explicit consent, unless necessary to fulfill a legal obligation; Reporting under a pseudonym is possible;
  • We keep you informed about the progress in resolving the issue;
  • In our communication concerning the reported issue, we, upon request, acknowledge your name as the discoverer;
  • As an expression of gratitude for your assistance, we offer a reward for each report on an unknown security issue. The reward is determined by the severity of the flaw and the quality of the report.

We aim to resolve all issues and are willing to participate in any post-resolution publications regarding the matter.

Necessary

Necessary cookies help make a website more usable by enabling basic functions such as page navigation and access to secure areas of the website. Without these cookies, the website cannot function properly.

Name
Provider
Goal
Expiration period
Type
Name
tTf
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tTE
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tTDu
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tTDe
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tPL
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tnsApp
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tC
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tAE
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tADu
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
tADe
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
t3D
Provider

www.fundaments.nl

Goal

The cookie is linked to a bundle of cookies that serve to retrieve and display content. These cookies maintain the correct state of font, blog, photo, slides, colour themes, and other website settings.

Expiration period
Persistent
Type
HTML Local Storage
Name
rc::c
Provider
Goal

This cookie is used to distinguish between human users and bots.

Expiration period
Session
Type
HTML Local Storage
Name
rc::a
Provider
Goal

This cookie is used to distinguish between human users and bots. Helping the website in generating precise reports on website usage

Expiration period
Persistent
Type
HTML Local Storage
Name
CraftSessionId
Provider

www.fundaments.nl

Goal

Sets a unique session ID. This allows the website to gather visitor behavior data for statistical analysis.

Expiration period
Session
Type
HTTP Cookie
Name
CRAFT_CSRF_TOKEN
Provider

www.fundaments.nl

Goal

Ensures browsing security by preventing cross-site requests from being falsified. This cookie is essential for the security of the website and visitor.

Expiration period
Session
Type
HTTP Cookie
Name
collect
Provider
Goal

Used to send data to Google Analytics about the visitor's device and behavior. Tracks visitors across devices and marketing channels.

Expiration period
Session
Type
Pixel Tracker
Name
ads/ga-audiences
Provider
Goal

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor's online behaviour across websites.

Expiration period
Session
Type
Pixel Tracker
Name
_gid
Provider

www.fundaments.nl

Goal

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

Expiration period
1 day
Type
HTTP Cookie
Name
_gat
Provider

www.fundaments.nl

Goal

Used by Google Analytics to slow down request speed

Expiration period
1 day
Type
HTTP Cookie
Name
_ga
Provider

www.fundaments.nl

Goal

Registers a unique ID that is used to generate statistical data on how the visitor uses the website.

Expiration period
2 years
Type
HTTP Cookie
Preferences

Preference cookies allow a website to remember information that influences the behavior and design of the website, such as your preferred language or the region where you live.

Name
Provider
Goal
Expiration period
Type
Name
lang [x2]
Provider
Goal

Remembers the language version selected by the user for a website

Expiration period
Session
Type
HTTP Cookie
Statistics

Statistical cookies help website owners understand how visitors use their websites by collecting and reporting data anonymously.

Name
Provider
Goal
Expiration period
Type
Name
p.gif
Provider
Goal

Tracks unique fonts used on the website for internal analysis. The cookie does not record visitor data.

Expiration period
Session
Type
Pixel Tracker
Marketing

Marketing cookies are used to track visitors when they visit different websites. Their goal is to gather information that is tailored to and relevant to the individual user. This information becomes more valuable to us.

Name
Provider
Goal
Expiration period
Type
Name
yt-remote-session-name
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Session
Type
HTML Local Storage
Name
yt-remote-session-app
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Session
Type
HTML Local Storage
Name
yt-remote-fast-check-period
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Session
Type
HTML Local Storage
Name
yt-remote-device-id
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Persistent
Type
HTML Local Storage
Name
yt-remote-connected-devices
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Persistent
Type
HTML Local Storage
Name
yt-remote-cast-installed
Provider
Goal

Stores the preferences of the user’s video player with embedded YouTube videos

Expiration period
Session
Type
HTML Local Storage
Name
YSC
Provider
Goal

Records a unique ID to monitor statistics regarding the YouTube videos viewed by the user

Expiration period
Session
Type
HTTP Cookie
Name
VISITOR_INFO1_LIVE
Provider
Goal

Strives to estimate users’ bandwidth on pages with integrated YouTube videos

Expiration period
179 days
Type
HTTP Cookie
Name
UserMatchHistory
Provider
Goal

Used to track visitors across various website in order to present relevant advertisements based on visitor preferences

Expiration period
29 days
Type
HTTP Cookie
Name
test_cookie
Provider
Goal

Used to check if the user’s browser supports cookies

Expiration period
1 day
Type
HTTP Cookie
Name
lissc
Provider
Goal

Operated by the social networking service, LinkedIn, to track the usage of embedded services

Expiration period
1 year
Type
HTTP Cookie
Name
lidc
Provider
Goal

Operated by the social networking service, LinkedIn, to track the usage of embedded services

Expiration period
1 day
Type
HTTP Cookie
Name
IDE
Provider
Goal

Managed by Google DoubleClick to track and report website user actions post-viewing or clicking on any of advertisements. The goal is measuring ad effectiveness and presenting targeted ads to the user.

Expiration period
1 year
Type
HTTP Cookie
Name
hubspotutk
Provider

www.fundaments.nl

Goal

Keeps track of a visitor's identity. This cookie has passed to the marketing platform HubSpot on form submission and used when de-duplicating contacts.

Expiration period
1 year
Type
HTTP Cookie
Name
GPS
Provider
Goal

Registers a unique ID on mobile devices to enable tracking based on geographic GPS location.

Expiration period
1 day
Type
HTTP Cookie
Name
embed/v3/counters.gif
Provider
Goal

Collects data on user preferences and/or interaction with web campaign content. This utilized on the CMR campaign platform that website owner use to promote events and products.

Expiration period
Session
Type
Pixel Tracker
Name
bscookie
Provider
Goal

Operated by the social networking service, LinkedIn, to track the usage of embedded services

Expiration period
2 years
Type
HTTP Cookie
Name
bcookie
Provider
Goal

Operated by the social networking service, LinkedIn, to track the usage of embedded services

Expiration period
2 years
Type
HTTP Cookie
Name
__ptq.gif
Provider
Goal

Sends data to the marketing platform Hubspot about the visitor's device and behaviour. Tracks the visitor across devices and marketing channels.

Expiration period
Session
Type
Pixel Tracker
Name
__hstc
Provider

www.fundaments.nl

Goal

Gathers statistical data regarding the user’s website visits, such as visit counts, average time spent on the website and which pages were loaded. The objective is to segment website users based on factors such as demographics and geographical location. This enables media and marketing agencies to structure and understand their target audiences in order to facilitate customized online advertisements.

Expiration period
1 year
Type
HTTP Cookie
Name
__hssrc
Provider

www.fundaments.nl

Goal

Gathers statistical data regarding the user’s website visits, such as visit counts, average time spent on the website and which pages were loaded. The objective is to segment website users based on factors such as demographics and geographical location. This enables media and marketing agencies to structure and understand their target audiences in order to facilitate customized online advertisements.

Expiration period
Session
Type
HTTP Cookie
Name
__hssc
Provider

www.fundaments.nl

Goal

Gathers statistical data regarding the user’s website visits, such as visit counts, average time spent on the website and which pages were loaded. The objective is to segment website users based on factors such as demographics and geographical location. This enables media and marketing agencies to structure and understand their target audiences in order to facilitate customized online advertisements.

Expiration period
1 day
Type
HTTP Cookie