Rules of engagement
The following rules apply to all Belfius projects on the intigriti platform:
- Researchers must adhere to the "Binding Ethical hacking Researchers Guidelines" (esp. art. 6 and art. 8) as published by Intigriti.
- Researchers must always operate within the legal boundaries when investigating Belfius
- Researchers are not allowed to make any changes to Belfius systems or data
- Researchers are not allowed to delete any data
- It is not allowed to perform any tests that could have disruptive results (e.g. brute forcing, (D)DOS attacks…)
- It is forbidden to share or publicize any bank or customer data discovered during testing. This includes publishing vulnerability details on blogposts and media articles
- It is forbidden to exfiltrate any Belfius data
- Accessing data from other clients is forbidden unless absolutely necessary to prove a vulnerability exists
- The use of brute forcing techniques, such as repeatedly entering passwords, is not allowed
- Never insert a backdoor in Belfius systems, not even as a proof of concept
- Researchers are not eligible for a reward if they are an employee of Belfius, or have worked under contract for Belfius in the past year. The aforementioned researchers are also not allowed to aid other researchers in any way.
- After the investigation, the researcher will destroy all tangible knowledge obtained as part of the investigation and will never use this knowledge outside of Belfius's programs on intigriti.
For obvious reasons we can only allow submissions or applications for our program with a valid Intigriti account.
It will only take 2 minutes to create a new one or even less to log in with an existing account, so don't hesitate and let's get started. We would be thrilled to have you as part of our community.






























