Report a Vulnerability

Your security is important to us. If you believe you've found a security vulnerability in BlueBitSoft's services, please let us know right away.

Introduction

BlueBitSoft is committed to ensuring the security of our users and their data. We value the contributions of security researchers and the broader security community in helping us maintain a safe and secure platform. This Vulnerability Disclosure Policy (VDP) outlines how to report security vulnerabilities to us, what you can expect from us, and our commitments to those who report vulnerabilities in good faith.

This policy describes what systems and types of research are covered, how to send us vulnerability reports, and how long we ask security researchers to wait before publicly disclosing vulnerabilities.

Authorization (Safe Harbor)

If you make a good faith effort to comply with this policy during your security research, we will consider your research to be authorized. BlueBitSoft will not initiate or support legal action against you for security research activities that adhere to this policy. Should legal action be initiated by a third party against you for activities that were conducted in accordance with this policy, we will make this authorization known.

Guidelines for Researchers

Under this policy, "research" means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Provide us a reasonable amount of time (typically 90 days) to resolve the issue before you disclose it publicly.
  • Do not submit a high volume of low-quality reports.

Once you've established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must stop your test, notify us immediately, and not disclose this data to anyone else.

Test Methods Not Authorized

The following test methods are not authorized:

  • Network denial of service (DoS or DDoS) tests or other tests that impair access to or damage a system or data.
  • Physical testing (e.g., office access, open doors, tailgating).
  • Social engineering (e.g., phishing, vishing), or any other non-technical vulnerability testing.
  • Attacks against BlueBitSoft employees, users, or third-party providers.
  • Spamming.

Scope

This policy applies to the following BlueBitSoft systems and services:

  • The BlueBitSoft website and platform, specifically `*.bluebitsoft.net`.
  • Any mobile applications officially released by BlueBitSoft.

Any service not expressly listed above, such as any connected third-party services or systems from our vendors, are excluded from the scope of this policy. Vulnerabilities found in vendor systems should be reported directly to the vendor according to their disclosure policy. If you are unsure whether a system is in scope, please contact us at [email protected] before starting your research.

Reporting a Vulnerability

We encourage you to report vulnerabilities via email to [email protected]. Please use a descriptive subject line to help us triage your report (e.g., "Potential XSS Vulnerability in User Profile Page").

To help us assess and validate your report, please include the following information if possible:

  • A clear description of the vulnerability, including its location (e.g., URL, specific feature).
  • The potential impact of the vulnerability.
  • Detailed steps to reproduce the vulnerability (Proof-of-Concept scripts, screenshots, and screen recordings are helpful).
  • Any tools used, including version numbers.
  • Your name and contact information (optional, but helpful for communication). Reports can be submitted anonymously.

Information submitted under this policy will be used for defensive purposes only. If your findings include newly discovered vulnerabilities that affect all users of a product or service, we may share your report with relevant third parties (e.g., CISA, the affected vendor) as part of a coordinated vulnerability disclosure process. We will not share your name or contact information without your express permission.

What to Expect From Us

When you report a vulnerability to us in accordance with this policy:

  • We will acknowledge receipt of your report within 3 business days (if you provide contact information).
  • We will investigate your report and work to validate the vulnerability.
  • We will maintain an open dialogue with you throughout the process, providing updates on our progress as appropriate.
  • We will notify you when the vulnerability has been remediated.
  • We do not offer monetary rewards (bug bounties) at this time, but we appreciate your efforts and may offer public acknowledgment (with your permission) for valid reports that help us improve our security.

Public Disclosure

We ask that you refrain from publicly disclosing the vulnerability until we have had a reasonable amount of time (typically 90 days from our acknowledgment of your report) to investigate and remediate the issue. We are committed to transparency and will coordinate with you on public disclosure if appropriate.

Questions

If you have any questions regarding this Vulnerability Disclosure Policy, please contact us at [email protected].