Skip to content
SKY DUST LogoSKY DUST
PlatformSmart Fitting MirrorAboutContact
Log inStart LiftOFF, from €39/month
SKY DUST LogoSKY DUST

AI platform for operations, growth and knowledge. Assistants prepare; you approve.

Microsoft for StartupsAlumni 2021-2023

Platform

  • Platform overview
  • AI for email
  • AI automation
  • Client portal
  • Pricing

Products

  • SKY DUST LiftOFF
  • Smart Fitting Mirror
  • Custom AI development

Information

  • About SKY DUST
  • Partners
  • Blog
  • Contact
Privacy policyTerms of ServiceCookie policyAll legal documents
© 2026 SKY DUST · Sky Dust Platform B.V. · Hanzeplein 11 - 27, 8017 JD Zwolle · KvK 86188216 · BTW NL863889608B01
CBS AI Monitor 2025
All legal documents

Responsible Disclosure Policy

The security of our systems and customer data comes first. Despite our care, if you have found a weakness in skydust.io or the platform, we would like to hear about it so we can fix it quickly. This policy describes how to report safely and what you can expect from us.

Last updated: 14 July 2026

1. How to report a vulnerability
  • Email your findings to karlo.timmerman@skydust.io with the subject "Responsible disclosure".
  • Describe the issue as concretely as possible: which URL or feature, the steps to reproduce it, and the potential impact.
  • Attach screenshots or a proof of concept where possible.
  • Leave contact details so we can ask questions; anonymous reports are also welcome.
2. Ground rules

To keep the disclosure responsible, we ask that you:

  • Do not exploit the vulnerability: do not download, modify or delete other people's data, and do not disrupt the service.
  • Do not go further than necessary to demonstrate the issue.
  • Do not share the vulnerability with others until it has been fixed.
  • Do not use physical attacks, social engineering, phishing, spam or (D)DoS.
3. What you can expect from us
  • We confirm receipt of your report within 3 business days.
  • We provide an initial assessment and an expected resolution timeline within 10 business days.
  • We keep you informed of progress and let you know when the issue is fixed.
  • If you follow the ground rules, we will not pursue legal action in connection with your report.
  • With your consent, we credit you as the discoverer; otherwise we treat your report confidentially.
4. Out of scope
  • Reports about missing best practices without a demonstrable security risk (such as missing security headers without an exploit).
  • Vulnerabilities in third-party services; report those to the relevant vendor.
  • Automated scanner output without your own analysis.