I'm a private, independant, starting privacy auditor, full of passion, yet still learning. My Proton email address is:
descent-audit AT proton DOT meI don't do penetration testing, I'll never access a system from within, however, if I do find privacy related info, I follow the Responsible Disclosure Procedure.
The NCSC has information about this you can verify:
In vijf stappen naar CVD-beleid
It contains a link to a PDF titled: "CoordinatedVulnerabilityDisclosure_2019"
- Belang van responsible disclosure