Coordinated Vulnerability Disclosure Policy
Last updated: 8th of July 2026
Version: 1.0
1. Purpose
Mobilexpense is committed to maintaining the security of its products and services. Security researchers, customers, and other members of the security community play an important role in helping identify vulnerabilities before they can be exploited.
This Coordinated Vulnerability Disclosure (CVD) Policy explains how to report suspected security vulnerabilities, what types of testing are authorised under this policy, and how Mobilexpense will coordinate the assessment, remediation, and disclosure of reported vulnerabilities.
2. Our position
This policy is intended for security researchers, customers, partners, and other individuals who discover or suspect a security vulnerability affecting Mobilexpense products or services.
Mobilexpense welcomes reports of security vulnerabilities affecting our products and services. We treat security researchers as partners and commit to coordinating openly when issues are reported in good faith.
This policy is aligned with ISO/IEC 29147 (vulnerability disclosure), ISO/IEC 30111 (vulnerability handling processes), and the coordinated vulnerability disclosure framework published by the Centre for Cybersecurity Belgium (CCB).
3. Definitions
CVD (Coordinated Vulnerability Disclosure): The process by which a Security Researcher privately reports a Security Vulnerability to Mobilexpense, and both parties coordinate on its investigation, remediation, and any subsequent public disclosure, so that risk to users is minimized before details are made public.
Customer Tenants: The logically isolated environments, instances, accounts, or data partitions that Mobilexpense provisions for individual customers within its multi-tenant systems, including all data, configurations, and resources contained within them.
Good Faith: Acting honestly, without malicious intent, and consistent with this policy including accessing only the minimum data necessary to demonstrate a vulnerability; avoiding privacy violations, service degradation, and destruction or exfiltration of data; and making a genuine effort to avoid harm to Mobilexpense, its users, and third parties.
In-Scope Systems (or "Systems"): The Mobilexpense assets, domains, products, and services expressly listed as eligible for testing under this policy. Anything not listed is considered out of scope.
Personal Data: Any information relating to an identified or identifiable natural person, as defined under applicable data protection laws (including the EU/UK GDPR and CCPA/CPRA). This includes, without limitation, names, email addresses, identification numbers, location data, and online identifiers.
Proof of Concept (PoC): A benign demonstration such as a screenshot, log excerpt, or minimal code, that establishes the existence and exploitability of a Security Vulnerability without causing harm or accessing more data than necessary.
Public Disclosure: Any release, publication, or communication of information about a Security Vulnerability to persons other than Mobilexpense and the reporting Security Researcher.
Remediation: The actions taken by Mobilexpense to fix, mitigate, or otherwise resolve a reported Security Vulnerability.
Safe Harbor: The protections Mobilexpense extends to Security Researchers who act in Good Faith and in compliance with this policy, under which Mobilexpense agrees not to pursue or support legal action against them for their research activities.
Security Researcher: Any individual or entity that investigates Mobilexpense's systems, products, or services to identify Security Vulnerabilities and reports them in accordance with this policy. Referred to herein as "you" or "the researcher."
Security Vulnerability: A weakness, flaw, or misconfiguration in a system, application, network, or process that could be exploited to compromise the confidentiality, integrity, or availability of that system or the data it processes.
Sensitive Data: Any non-public information whose exposure could cause harm, including Personal Data, credentials, authentication tokens, encryption keys, financial information, and Mobilexpense confidential or proprietary information.
Vulnerability Report (or "Report"): The submission a Security Researcher makes to Mobilexpense describing a suspected Security Vulnerability, including supporting details, reproduction steps, or a Proof of Concept.
4. Scope
This policy applies to:
- The MXP product and its API
- The Declaree product and its API
- The Mobilexpense.com corporate website and its subdomains
- Production infrastructure owned and operated by Mobilexpense
- Code developed by Mobilexpense and by our development partners on our behalf
5. Out of scope
-
Denial-of-service or resource-exhaustion testing of any kind
- Social engineering of Mobilexpense employees, customers, or partners
- Physical attacks against Mobilexpense premises or personnel
- Vulnerabilities requiring physical access to a victim's device or attacks against pre-compromised user accounts
- Findings produced by automated scanners without manual verification and a working proof of concept
- Self-XSS, clickjacking, or username/email enumeration without demonstrable impact
- Issues in third-party libraries or services where no working exploitation path against our deployment has been demonstrated
- Customer-specific configurations managed by the customer (tenant settings, identity provider configuration, user permissions, password policies)
- Third-party services that we do not operate (cloud platforms, browsers, end-user devices)
- Missing security headers, weak TLS configurations, or other best-practice deviations without a demonstrable exploitation path
- Vulnerabilities affecting end-of-life or unsupported versions of our products
6. Rules of engagement
When testing within scope, we ask that you:
- Use only accounts you have created yourself. Do not test against customer tenants or user accounts you do not own.
- Stop testing as soon as a vulnerability is confirmed. Do not deepen exploitation, escalate privileges further than necessary, or pivot to additional systems.
- Limit data exposure. Do not access, modify, retain, copy, or destroy data (including personal data) beyond what is strictly necessary to demonstrate the vulnerability. If you incidentally access personal data, stop immediately, do not retain copies, and notify us in your report so that we can assess any reporting obligations.
- Preserve service availability. Do not degrade or interrupt our services, and do not run load-impact or denial-of-service tests.
- Do not coerce. Do not extort, threaten, or otherwise pressure Mobilexpense, our customers, or our partners.
7. Safe harbor
We will not initiate civil or criminal action against researchers who comply with §6 (Rules of engagement) and §10 (Coordinated disclosure). We will also instruct our employees, contractors, and development partners not to do so.
If a third party initiates legal action against you for activities we consider compliant with this policy, we will make our position publicly known.
This commitment is aligned with the framework published by the Centre for Cybersecurity Belgium (CCB) and the relevant provisions of Belgian law on coordinated vulnerability disclosure.
8. How to report
Send your report to security@mobilexpense.com.
For sensitive details, encrypt your message using our PGP key, available here.
Fingerprint: 7107DA0B2DE35253890F4A295B6DE4866469E500
Please include:
- A clear description of the vulnerability and its potential impact
- The affected product, URL, endpoint, or component
- Steps to reproduce, including any proof-of-concept code or screenshots
- Confirmation of whether personal data was incidentally accessed during testing
- Your preferred contact details and whether you wish to be publicly acknowledged
Anonymous reports are accepted. We will still triage and remediate them. However, we cannot send status updates, coordinate disclosure timelines, or offer recognition without contact details.
We accept reports in English, French, or Dutch.
9. What you can expect from us
-
Acknowledgment within 5 business days of receiving your report
- Initial triage decision (valid, duplicate, out-of-scope) within 10 business days
- Status updates at least every 30 days while the report remains open
- Notification when the vulnerability is remediated or the report is closed
We will treat your report confidentially and will not share your identity with third parties without your consent, except where required by law.
10. Coordinated disclosure
We ask that you do not publicly disclose the vulnerability until we confirm that it has been remediated, or until 90 days have passed since your initial report, whichever comes first. For vulnerabilities with broad customer impact or significant remediation complexity, we may request an extension by mutual agreement.
In return, we commit to:
- Engaging in good faith and progressing remediation without undue delay
- Not invoking this clause to indefinitely delay disclosure of issues we cannot or will not fix
- Not retaliating against researchers who publish in good faith after the disclosure window has elapsed or after remediation is complete
11. Recognition
With your consent, we will acknowledge your contribution on our public list of contributors. You may choose a pseudonym, request no public acknowledgement, or withdraw acknowledgment at any time.
We do not offer monetary rewards under this policy. This is a coordinated disclosure programme, not a bug bounty.
12. Governing law and policy update
This policy is governed by Belgian law. Nothing in this policy is intended to limit any legal protection available to researchers under applicable Belgian or EU law.
We may update this policy. The version in effect at the time of your report is the version that applies to your report. Previous versions are available on request at security@mobilexpense.com.
Frequently asked questions
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.
Lorem ipsum dolor sit amet, consectetuer adipiscing elit. Aenean commodo ligula eget dolor. Aenean massa. Cum sociis natoque penatibus et magnis dis parturient montes, nascetur ridiculus mus. Donec quam felis, ultricies nec, pellentesque eu, pretium quis, sem. Nulla consequat massa quis enim. Donec pede justo, fringilla vel, aliquet nec, vulputate eget, arcu. In enim justo, rhoncus ut, imperdiet a, venenatis vitae, justo. Nullam dictum felis eu pede mollis pretium. Integer tincidunt. Cras dapibus. Vivamus elementum semper nisi.