Security
Are you a security analyst who has identified vulnerabilities in our systems? If so, we look forward to working with you to eliminate these vulnerabilities before they can be exploited by attackers. We work every day to strengthen our data protection and service availability by improving our systems and processes. However, our systems are not perfect and do have weaknesses. This is why we want to join forces with security researchers who have identified vulnerabilities on our websites. Read on to learn more about our Rules of Engagement and how to contact us.
Security Contact
Contact: e-mail@cetl.lu
Coordinated Vulnerability Disclosure Policy
Rules of engagement ¦ out of scope
This policy does not apply to:
- complaints about our service offering;
- complaints or questions about the availability of our services;
- reports of fraud or suspected fraud;
- email scams or phishing emails;
- reports of viruses or malware;
- vulnerability reports that contain results from automated tools or scans but lack explanatory documentation. These are not considered valid vulnerability reports.
The following examples are also considered out of scope:
- DOS/DDoS
- Brute force
- Spam, email scams or phishing emails
- Open TCP ports (unless they have specific vulnerabilities).
- HTTP error messages, such as status code 404 (except where information is disclosed in error messages).
- Access to non-critical data already in the public domain (e.g. robots.txt).
- Clickjacking or potential clickjacking
- Lack of optional features such as SPF, DKIM, DMARC, HPKP, etc.
- Outdated versions of software or JavaScript libraries with no proof of concept exploit
- Individual aspects of SSL/TLS configuration, such as a lack of forward secrecy and SSL vulnerabilities that cannot be attacked remotely, as well as weak cipher suites.
- Supposed vulnerabilities in HTTP header fields
- The ability to determine usernames via brute force
- HTTP OPTIONS method
- Lack of CAPTCHAs
- Lack of secure or HTTP-only flags for non-critical cookies
Rules of engagement ¦ in scope
We are looking for reports on vulnerabilities detected in the following areas:
- Cross-site scripting (XSS);
- Remote code execution (RCE);
- Cross-site request forgery (CSRF, XSRF) on interactive websites;
- SQL injection;
- XML entity expansion (XXE);
- Cryptographic vulnerabilities;
- Authentication and authorisation issues;
- Versions banners;
- Server-side request forgery (SSRF).
Domains in scope:
- *.cetl.lu
- *.financialcrime.lu
Disclaimer
As you conduct your security research, it is possible that your actions may break the law. However, if you act in good faith and adhere to this Vulnerability Disclosure Policy, we will not report your research to the relevant authorities. Please act responsibly. Follow the rules set out in this Vulnerability Disclosure Policy.
Do not publish your report. Instead, share your findings with us and give us time to fix any vulnerabilities you may have discovered. We will be in touch to let you know what steps we will take in response to your report and will be transparent about how and when we will deal with it.
- Make sure that you cause no harm while we investigate the reported vulnerability.
- Do not use social engineering to access our IT systems.
- Your research must never interrupt our online or other services.
- Your research must not result in the disclosure of our data or that of our customers.
- Do not build backdoors into our systems, even if it is just to demonstrate a security vulnerability. Creating a backdoor will only further compromise system security.
- Do not make any changes or delete data from our system. If your research requires data to be copied from the system, limit these copies to what is necessary for your research purposes.
- If one dataset is sufficient, do not copy more than one.
- Please do not include any personal data obtained from our systems when submitting a report.
- Blur names, email addresses, etc. in your screenshots, and black out the contents of server responses before sending this information to us.
- Do not make any changes to the system.
- Do not attempt to penetrate the system any more than is necessary. If you successfully penetrate the system, do not share your access with others.
- Do not use brute-force techniques to gain access to the system, e.g. repeatedly guessing passwords.
- Do not use techniques that could affect the availability of our services and/or online services.
- Do not post on the internet or social media.
- Run your tests as an unauthenticated user. Do not use an account for your tests and do not create new accounts.
- All findings must be accompanied by proof of concept. We do not accept theoretical attacks.
How do I report a vulnerability?
Please provide a detailed description of the issue, including all available evidence.
Include the following information in your report:
- Description of the vulnerability
- Details of the steps you took
- Full URL
- Details of all potentially affected objects (e.g. filter or entry fields)
- Details of the impact
- Recommendation as to how things could be improved
- Screenshots are also welcome.
- We can only accept reports in English or German. Send an email with a brief description of the issue to e-mail@cetl.lu
- Unless you indicate otherwise, we will respond to the email address from which the report was sent.
As of August 2026