BTB Dots
BitsToBug
Contact

BitsToBug Studios LLP

Responsible Disclosure Policy

Effective date: 15 July 2026Last updated: 15 July 2026

BitsToBug Studios LLP welcomes reports from security researchers. This Policy explains how to report a vulnerability in our systems and what you can expect from us.

1. Scope

This Policy covers https://www.bitstobug.com and systems owned and operated by BitsToBug. It does not cover systems owned by our clients. If you believe you have found a vulnerability in a client system, report it to us and we will coordinate with the client. Do not test client systems.

2. How to report

Send your report to shreyansh@bitstobug.com with the subject line “Security Disclosure”. Please include a description of the vulnerability, the steps required to reproduce it, the potential impact, and any supporting evidence such as logs or screenshots. Reports may be submitted in English.

3. Our commitment to you

StageTimeline
Acknowledgement of your reportWithin 2 business days
Initial assessment and triageWithin 5 business days
Status updateEvery 10 business days until resolution
Remediation target for critical issues30 days from confirmation

We will not pursue legal action against researchers who act in good faith and in accordance with this Policy. With your permission, we are happy to credit you publicly once the issue is resolved.

4. Rules of engagement

  • Act in good faith, and avoid privacy violations, data destruction, and degradation of service.
  • Use only your own accounts or test accounts, and do not access, modify or retain data belonging to others.
  • Do not conduct denial of service testing, social engineering, physical attacks, or spam.
  • Do not publicly disclose the issue until we have confirmed remediation, or ninety days have passed from your report, whichever is earlier.
  • Stop testing and report immediately if you encounter personal data.

5. Out of scope

  • Reports from automated scanners without demonstrated exploitability.
  • Missing best practice headers or configuration issues with no demonstrated security impact.
  • Social engineering of our personnel, clients or vendors.
  • Vulnerabilities in third party services we do not control.
  • Reports requiring physical access to a device, or an already compromised device.

6. Rewards

We do not currently operate a paid bug bounty programme. We recognise valid reports with written acknowledgement and, with your consent, public credit.