Vlaander LTD
VLAANDER LTD · RC 8298878INDEPENDENTLY · SECURITY-REVIEWEDSIGNED RELEASES · SHA-256 PINNEDDISCLOSURE · SALES@VLAANDER.COM
§00 — Security Center

Provenance, disclosure, and review — published, not promised.

Vlaander LTD publishes the policies, contacts, and verification paths that govern every asset we sell. The disclosure policy below is in force today. The review register, signing key, SBOMs, and threat models drop in here as facts land — never as marketing, never as placeholders.

§01

Disclosure policy.

Acknowledgement
We acknowledge security reports within 24 hours.
Disclosure window
90 days from acknowledgement, extendable by mutual agreement for active remediation.
Safe harbor
Good-faith research on Vlaander products is welcomed. We will not pursue legal action against researchers who follow this policy.
Reward
We do not run a paid bounty programme. We will publicly credit reporters who consent to it on this page.
Contact
sales@vlaander.com — the only legitimate channel for security correspondence with Vlaander LTD.
§02

Provenance commitments.

Every release is signed (ed25519). Every shipped artifact carries a SHA-256 hash pinned on its product page. Every independent security review is published in full — firm, date, scope, findings, remediation status.

The phishing rule. The only channel through which we will ever ask you to act on a security message is an email from sales@vlaander.com — our single monitored inbox. We will never ask you to act through any other address. And release integrity never rests on trusting a message: every release is independently verifiable against the ed25519 signing key and the procedure in §04. If a release verification fails, do not run the binary, do not extract the source, and email sales@vlaander.com.

§03

Incident history.

Vlaander LTD has not disclosed a security incident. This page will be updated within 5 business days of any disclosure-eligible incident, and the entry will remain on this page indefinitely.

§04

Verify a release.

This procedure is in force for every asset we sell. It does not depend on trusting Vlaander — it lets you confirm, on your own machine, that what you received is what we shipped. Run it before you extract or build any source.

  1. On acquisition you receive the release tarball, its signed provenance manifest, and the manifest’s .sig over a secure channel — the source is never a public download. The SHA-256 for each release is published on the asset’s product page, so you verify what you received against a digest we committed to publicly.
  2. Confirm the digest: sha256sum <asset>-<version>.tar.gz and compare byte-for-byte against the SHA-256 pinned on the product page.
  3. Verify the signature against the Vlaander signing key (ed25519). The key fingerprint is published below.
  4. If either check fails, do not extract the source and do not run anything. Email sales@vlaander.com — a failed verification is a security event.
Signing key fingerprint (ed25519)
Publishing 2026-Q3 — publishes here the moment the signing key is generated; the procedure above is stable and will not change when it lands.
§05

Publishing on this page.

The following surfaces are canonical and committed; they appear on this page the moment the underlying facts are real, never before. We refuse to substitute marketing for evidence.

Forthcoming
  • Signing key fingerprint (the verification procedure above is already in force; the published key lands here)
  • Independent security review summary (per product: reviewer, date, scope, findings, remediation)

To be notified by email when any of the above publishes, email sales@vlaander.com with the subject “notify on publish”.