Brussels Airlines Responsible Disclosure Statement | Brussels Airlines
  • Go to navigation
  • Go to main content
  • Go to search
  • Go to search
  • Go to footer
Brussels
Brussels logo, back to homepage
 
Help
HomeBrussels Airlines Responsible Disclosure Statement

Main content

Brussels Airlines Responsible Disclosure Statement

Responsible Disclosure Statement 

At Brussels Airlines, we consider the safety and continuity of our online services as one of our top priorities. Our specialists are continually working to optimise our systems and processes, yet despite all the effort we put in to securing our systems, vulnerabilities may still be present. 

We investigate all reports of security vulnerabilities affecting our web presence. If you are a security researcher and you believe you have found a security vulnerability, please help us by reporting it so that we can work together to improve the safety and reliability of our systems. 

You can report vulnerabilities by joining the Intigriti bug bounty programme and registering as a researcher: 

​https://www.intigriti.com 

Intigriti is a crowdsourced security platform where security researchers and companies meet. As an ethical hacking and bug bounty platform, Intigriti aims to identify and tackle vulnerabilities in a cost efficient way. The platform facilitates online security testing through collaborating with experienced researchers.

As an Intigriti researcher, you can earn good money. If you are willing to go public with your responsible hacking activities, you can receive financial rewards. Intigriti pays out rewards for every bug you manage to find and submit as the first researcher. Please be aware, Intigriti does not accept registrations from anonymous researchers. 

If your vulnerability report is valid and you would like to be recognised for your contribution, we will gladly add you to our “Brussels Airlines InfoSec Hall of Fame”, by name or anonymously. Rest assured, we will only add you to our “Hall of Fame” if you explicitly request this. 

If you prefer not to provide your name and contact details, you can report a vulnerability directly to Brussels Airlines. However, you should consider that without this information we will be unable to discuss the next steps with you, or add you to our “Hall of Fame”. 

To report a vulnerability directly to us, please send an e-mail to our security team: 

​InfoSec@brusselsairlines.com

Our specialists will read your report and start working on it right away. 

Please ensure that your e-mail is clear and succinct. In particular, please include the following information: 

  • Description of the discovered vulnerability or risk 
  • Evidence of the finding (e.g. Proof of Concept, video, screenshot, etc.) 
  • The steps you undertook 
  • The entire URL 
  • Objects possibly involved 

Examples of vulnerabilities could be: 

  • Cross-site scripting (XSS) vulnerabilities 
  • SQL injection vulnerabilities 
  • Remote Code execution 
  • Authentication bypass 
  • Encryption vulnerabilities 

To ensure that your testing remains lawful, refrain from using invasive or destructive techniques. Always adhere to these rules: 

  • Do not disrupt our online services. 
  • Do not use techniques that can influence the availability of our online services. 
  • Do not make any changes to the system. 
  • Do not modify or delete any data in the system. 
  • In case your finding requires a copy of the data from the system, do not copy more than your investigation requires. If one record is sufficient, do not copy more. 
  • Do not make any customer or business data public. 
  • Do not create a backdoor in any system. 
  • Do not attempt to penetrate the system more than required. In case you successfully penetrate the system, do not share gained access with others. 
  • Do not use any brute force techniques (e.g. repeatedly entering passwords) in order to gain access to the system. 
  • Do not use social engineering in order to gain access to our IT systems. 

To ensure the best outcome, please follow these guidelines: 

  • Create your report in Dutch, French, or English. Reports in other languages will not be processed. 
  • Give us enough details to enable us to reproduce the vulnerability. 
  • Allow us a reasonable amount of time to fix the vulnerability before making any information public. 
  • Consult with us before making any information public. 
  • Do not ask Brussels Airlines to compensate you for your report. 

You can expect the following commitments from us: 

  • We will let you know that we received your report. 
  • We will give you an estimate of how long the fix will take. 
  • We will tell you when we have fixed the vulnerability. 

Your personal information will only be used to approach you regarding your vulnerability report. We will not distribute your personal information to third parties without your permission. Should the law require us to provide your personal information to an authority we will ensure that the applicable authority treats your personal information confidentially. We will remain responsible for your personal information. 

Thank you for your support. 
Information Security Team - Brussels Airlines 

Last update: March 2019 

Footer

About us

  • Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Our company
  • Lufthansa Group
  • Corporate services  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Jobs
  • Press room
  • Destinations

Most visited pages

  • Check-in
  • My booking
  • Miles & More  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Group bookings
  • Arrivals & departures
  • Accessible travel

Get in touch with us

  • Contact
  • Subscribe to our newsletter

Social media

  • youtube.com  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • facebook.com  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Instagram  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Tiktok.com  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Linkedin  , Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
    Please note that with this link you are visiting an external website that may not follow the same privacy, security or accessibility policies.
  • Imprint
  • Data protection
  • Legal notices
  • Payment methods
  • Change privacy settings
Brussels
Homepage
Member of Lufthansa Group
Star Alliance
Homepage

Privacy Settings

We use cookies and similar technologies that are necessary to run the app and the website. Additional cookies are only used with your consent. We use them to access, analyse and store information such as the characteristics of your device as well as certain personal data (IP addresses, navigation usage, geolocation data or unique identifiers). The processing of your data serves various purposes: Analytics cookies allow us to analyse our performance to offer you a better online experience and evaluate the efficiency of our campaigns. Personalisation cookies give you access to a customised experience of our website with usage-based offers and support. Finally, Advertising cookies are placed by third-party companies processing your data to create audiences lists to deliver targeted ads on social media and the internet. You may freely give, refuse or withdraw your consent at any time using the link provided at the bottom of each page. You can consent to our use of cookies by clicking on Agree. For more information on which data is collected and how it is shared with our partners please read our privacy and cookie policy: Privacy Notice | Cookie Notice

These cookies are necessary to run the core functionalities of this website, e.g. security related functions. With these cookies we can also detect if you want to stay logged into your profile to provide you with fast access to our services after revisiting our website.

  • Monitor website traffic and optimize your user experience
  • Evaluate which marketing channels are performing better
  • Analyse aggregated data about usage of the website to understand our customers. Randomized identifiers shared with partners.

  • Store your preferences from previous visits
  • Collect user feedback to improve our website
  • Evaluate your interests to provide you unique customised content and offers

By selecting this category, the categories Analytics and Personalization will also be activated.

  • Make online and social advertising more relevant for you
  • Invite specific customer groups to reconnect with our products later
  • Share data with our advertising and social media partners via their third-party cookies to match your interests