Dutch Institute for Vulnerability Disclosure
- Company typePrivate
- Founded2019
- HeadquartersDen Haag, Netherlands
- Headcount101–250
- GTM typeB2B
- OfferingServices
Dutch Institute for Vulnerability Disclosure firmographics
Firmographics- Name
- Dutch Institute for Vulnerability Disclosure
- Legal name
- Stichting Dutch Institute for Vulnerability Disclosure
- Website
- https://divd.nl
- Company type
- Private
- Founded year
- 2019
- Operating status
- Operating
- Headcount range
- 101–250 employees
- Ownership category
- akta.pro rank
Dutch Institute for Vulnerability Disclosure industry classification
Industry- Product category
- Cybersecurity Services
- NAICS
- Security Systems Services (except Locksmiths) (561621)
- SIC
- Services-Detective, Guard & Armored Car Services (7381)
- akta.pro primary industry
- Security Systems Monitoring & Dispatch (SOC/Remote Guarding) (IMAIAEAF)
- akta.pro secondary industry
- Endpoint Forensics & Incident Response (DFIR) (HDADAEAJ)
Keywords
Where Dutch Institute for Vulnerability Disclosure is headquartered
LocationHeadquarters
- HQ city
- Den Haag
- HQ country
- Netherlands
- HQ region
- Europe
Offices1 record
Markets served
Dutch Institute for Vulnerability Disclosure business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Technology or R&D, Infrastructure, Operations, Personnel, Marketing or Sales
Revenue model
- Donations and Grants: DIVD is a non-profit organization funded through donations and grants. The organization accepts donations from individuals and organizations. Several partners provide financial support including NCTV (funding for 2023–2025), SIDN Fund, Digital Trust Center (funding in 2022), Topsector Energie, Bureau Veritas, ESET, and VMware Foundation (through licenses and hardware funding). Board members are volunteers and receive no compensation.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Monthly | Free Coordinated Vulnerability Disclosure Services |
Go-to-market motion1 record
Distribution channels5 records
Marketing channels7 records
Dutch Institute for Vulnerability Disclosure product offering
Product offeringCore offering
DIVD is a volunteer-run non-profit that performs internet-wide vulnerability scanning, assigns CVE identifiers as an official CVE Numbering Authority (Root CNA under ENISA), and coordinates disclosure of discovered vulnerabilities to affected organizations and individuals. The organization operates a Computer Security Incident Response Team (CSIRT) that publishes case files, notifies vulnerable system owners via direct email, and analyzes leaked credential databases to warn victims of compromise (including via the Operation Endgame collaboration with Dutch Police).
Product overview
Dutch Institute for Vulnerability Disclosure (DIVD) is a non-profit research institute operated by volunteers. It is not a traditional product company; rather, it provides coordinated vulnerability disclosure services, operating as an official CVE Numbering Authority (CNA). Its core offerings are its CSIRT operations (incident response, vulnerability scanning, and victim notification) and its CNA function (CVE ID assignment and disclosure management). Supporting these are DIVD Academy (educational e-learning), the DIVD Careers Portal (Google Workspace-hosted recruitment), and DIVD Community (Slack-based collaboration). The organization has a global reach and operates entirely for free, following principles of open, honest, and collaborative responsible disclosure.
Differentiator
Problem solved
Functional benefit
Products and services
- DIVD CSIRT Computer Security Incident Response Team that handles case management, vulnerability coordination, CVE assignment, and victim notification for discovered vulnerabilities. Operates as an official CVE Numbering Authority within the CVE ecosystem.
- DIVD CNA (CVE Numbering Authority) Official CVE Numbering Authority function that assigns unique CVE identifiers to vulnerabilities discovered by DIVD researchers or reported to DIVD for coordinated disclosure, within a defined scope of software vulnerabilities not covered by other CNAs. Publishes CVE records following a structured disclosure timeline.
- DIVD Academy Educational e-learning platform providing introductory courses (e.g., DIVD Introduction), training materials, and advanced research training for DIVD volunteer researchers. Engages in energy-sector research collaborations.
- Operation Endgame Victim Notification Victim notification service operated in collaboration with Dutch National Police and trusted partners (Have I Been Pwned, Spamhaus, NCSC, CSIRT-DSP, Digital Trust Center) to identify and notify victims of compromised credentials found in botnet and malware operations data.
Quantifiable outcome
- Over 1.4 million vulnerable IP addresses notified
- +3 more outcomes
Companies that use Dutch Institute for Vulnerability Disclosure
Customer profileNamed customers9 records
Segments5 records
Ideal customer profiles4 records
Dutch Institute for Vulnerability Disclosure technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Integration1 record
Feature5 records
Dutch Institute for Vulnerability Disclosure partnerships and signals
Strategic signalPartnerships
19 partnerships are on record, tiered core and minor.
- A2B InternetcoreErik Bais, owner of A2B-Internet helped DIVD get their own Autonomous System, providing DIVD with its own IP addresses (AS50559, 194.5.73.0/24) to scan from. This enables DIVD to conduct internet-wide vulnerability scanning from its own infrastructure.
- Atom86coreAtom86 sponsors connectivity and rack space for DIVD's scanning infrastructure, enabling the organization's internet-wide vulnerability scanning operations.
- BITcoreBIT sponsors hosting space for DIVD's websites and mail server capacity, supporting DIVD's web presence and communication infrastructure.
- CiscocoreCisco provides free training to DIVD and DIVD.academy, contributing to the professional development of DIVD's volunteer researchers.
- Digital Trust Center (DTC)coreThe Digital Trust Center provided funding to DIVD in 2022 and is listed as a trusted information sharing partner for coordinated vulnerability disclosure. DTC also provides funding for DIVD's vulnerability research.
- ElaadNLcoreDIVD collaborates with ElaadNL on the Energy project, converting newly discovered vulnerabilities in electric vehicle charging infrastructure and energy systems into CVEs.
- ElasticcoreElastic sponsors DIVD by providing an Enterprise license, enabling DIVD's teams to perform large-scale data analysis and power their SIEM solution for effective vulnerability detection and response.
- European Network for Cyber Security (ENCS)coreDIVD works together with ENCS on the Energy project to convert newly discovered vulnerabilities in energy sector systems into CVEs, particularly in smart grid and critical infrastructure.
- Internet Cleanup FoundationminorThe Internet Cleanup Foundation shares DIVD's mission of making the digital world safer and collaborates on vulnerability disclosure efforts.
- LunaViacoreDIVD has its office at LunaVia, which also helps with administrative tasks and acquiring funding for DIVD Academy.
- Rapid7coreRapid7 supports DIVD by sharing their scanning data for research purposes, contributing to DIVD's vulnerability detection capabilities.
- Schouten ZekerheidminorSchouten Zekerheid Makelaars in Assurantiën serves as DIVD's insurance intermediary and supports the organization and its cause.
- Schuberg PhiliscoreSchuberg Philis has provided DIVD with support from some of their employees and equipment for DIVD's scanning infrastructure.
- SecurityBridgeminorSecurityBridge supports DIVD with in-depth expertise on SAP security and provides resources to help scan the internet for vulnerabilities in SAP systems.
- SUPERPminorSUPERP supports DIVD by allowing some of their employees to contribute to Research and CSIRT activities.
- The Green VillageminorThe Green Village is organizing hack events together with DIVD, promoting cybersecurity education and awareness.
- Fox-ITcoreFox-IT scanned for vulnerable instances and collaborated with DIVD on Qlik Sense vulnerability research and Project Melissa, sharing scanning data for research purposes.
- NorthwavecoreNorthwave collaborated with DIVD as part of Project Melissa, contributing research on how Cactus ransomware exploits Qlik Sense vulnerabilities.
- Responders BVcoreResponders BV collaborated with DIVD as part of Project Melissa on identifying potential Cactus ransomware victims through Qlik Sense vulnerability research.
Scale indicators7 records
Recent moves7 records
Expansion highlights6 records
Dutch Institute for Vulnerability Disclosure competitors and assessment
Company assessmentDirect peers
- HackerOne: Largest commercial bug bounty and vulnerability disclosure platform. Operates a coordinated disclosure program and HackerOne-powered CVE Numbering Authority, directly comparable to DIVD's CNA/CSIRT function but delivered as a paid commercial product rather than a free non-profit service.
- Bugcrowd: Commercial crowdsourced cybersecurity platform offering bug bounty, vulnerability disclosure, and attack surface management. Direct peer in coordinated disclosure and CVE handling, differentiated by its paid, platform-based model versus DIVD's free volunteer model.
- Intigriti: European bug bounty and vulnerability disclosure platform headquartered in Belgium. Direct comparable in coordinated disclosure mechanics and target customer base, and notably employs DIVD's CSIRT Department Head in a senior triage role, indicating close ecosystem ties.
- Have I Been Pwned: Breach notification service run by Troy Hunt that operates as a trusted information sharing partner in DIVD's Operation Endgame work. Directly comparable in victim notification mechanics, with a larger consumer-facing brand and global individual user base.
- Zerocopter: Dutch responsible disclosure and bug bounty platform that hosts DIVD's own responsible disclosure portal. Operates in the same Dutch market and coordinates vulnerability reports to and from organizations, making it the closest national peer to DIVD.
- YesWeHack: European bug bounty and responsible disclosure platform operating a Vulnerability Disclosure Program (VDP) and Bug Bounty service. Comparable to DIVD in coordinated disclosure scope and European customer focus, though delivered as a paid commercial service.
Others
- ENISA (European Union Agency for Cybersecurity): EU's cybersecurity agency and DIVD's Root CVE Numbering Authority. Sets the regulatory framework within which DIVD operates and through which DIVD's CVE authority is recognized; not a competitor but a structural enabler and an increasingly important counterparty.
- NCSC-NL (National Cyber Security Center Netherlands): Dutch national CSIRT and DIVD's listed trusted information sharing partner. Performs overlapping vulnerability coordination, threat intelligence, and disclosure work, but as a government agency rather than an independent non-profit, and is itself a DIVD partner rather than a competitor.
Broad incumbents
- CISA (Cybersecurity and Infrastructure Security Agency): US federal cybersecurity agency operating a major CSIRT, vulnerability management, and coordinated disclosure function (including the Known Exploited Vulnerabilities catalog). Provides a useful scale and scope comparison for a future EU-level equivalent that DIVD could evolve toward.
- CERT Coordination Center (CERT/CC): Original federally-funded CSIRT based at Carnegie Mellon University, coordinating vulnerability disclosure globally for over 30 years. Direct operational analog to DIVD CSIRT and a fellow CVE Numbering Authority, with a broader historical scope and US-centric remit.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Dutch Institute for Vulnerability Disclosure social profiles
Digital presenceDutch Institute for Vulnerability Disclosure financial estimates
Financial estimateRevenue estimate
Valuation estimate
Dutch Institute for Vulnerability Disclosure leadership team
Management profileNumber of profiles
Profiles5 records
Dutch Institute for Vulnerability Disclosure funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Dutch Institute for Vulnerability Disclosure M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Dutch Institute for Vulnerability Disclosure
What does Dutch Institute for Vulnerability Disclosure do?
DIVD is a volunteer-run non-profit that performs internet-wide vulnerability scanning, assigns CVE identifiers as an official CVE Numbering Authority (Root CNA under ENISA), and coordinates disclosure of discovered vulnerabilities to affected organizations and individuals. The organization operates a Computer Security Incident Response Team (CSIRT) that publishes case files, notifies vulnerable system owners via direct email, and analyzes leaked credential databases to warn victims of compromise (including via the Operation Endgame collaboration with Dutch Police).
Is Dutch Institute for Vulnerability Disclosure a public or private company?
Dutch Institute for Vulnerability Disclosure is a private company. It is classified as nonprofit foundation owned and is currently operating.
When was Dutch Institute for Vulnerability Disclosure founded?
Dutch Institute for Vulnerability Disclosure was founded in 2019. It employs 101 to 250 people.
Where is Dutch Institute for Vulnerability Disclosure based?
Dutch Institute for Vulnerability Disclosure is headquartered in Den Haag, Netherlands, in the Europe region.
How does Dutch Institute for Vulnerability Disclosure make money?
One revenue line is on record: donations and Grants.
Who are Dutch Institute for Vulnerability Disclosure's main competitors?
Direct peers on record are HackerOne, Bugcrowd, Intigriti, Have I Been Pwned, Zerocopter and YesWeHack. Others are ENISA (European Union Agency for Cybersecurity) and NCSC-NL (National Cyber Security Center Netherlands). Broad incumbents are CISA (Cybersecurity and Infrastructure Security Agency) and CERT Coordination Center (CERT/CC).
Does Dutch Institute for Vulnerability Disclosure have an API?
No public API is recorded for Dutch Institute for Vulnerability Disclosure.
What industry is Dutch Institute for Vulnerability Disclosure in?
Dutch Institute for Vulnerability Disclosure's product category is Cybersecurity Services. Its primary akta.pro industry code is IMAIAEAF, Security Systems Monitoring & Dispatch (SOC/Remote Guarding), with a secondary code of HDADAEAJ, Endpoint Forensics & Incident Response (DFIR). Its NAICS code is 561621 and its SIC code is 7381.