BitsToBug Studios LLP
Responsible Disclosure Policy
BitsToBug Studios LLP welcomes reports from security researchers. This Policy explains how to report a vulnerability in our systems and what you can expect from us.
1. Scope
This Policy covers https://www.bitstobug.com and systems owned and operated by BitsToBug. It does not cover systems owned by our clients. If you believe you have found a vulnerability in a client system, report it to us and we will coordinate with the client. Do not test client systems.
2. How to report
Send your report to shreyansh@bitstobug.com with the subject line “Security Disclosure”. Please include a description of the vulnerability, the steps required to reproduce it, the potential impact, and any supporting evidence such as logs or screenshots. Reports may be submitted in English.
3. Our commitment to you
| Stage | Timeline |
|---|---|
| Acknowledgement of your report | Within 2 business days |
| Initial assessment and triage | Within 5 business days |
| Status update | Every 10 business days until resolution |
| Remediation target for critical issues | 30 days from confirmation |
We will not pursue legal action against researchers who act in good faith and in accordance with this Policy. With your permission, we are happy to credit you publicly once the issue is resolved.
4. Rules of engagement
- Act in good faith, and avoid privacy violations, data destruction, and degradation of service.
- Use only your own accounts or test accounts, and do not access, modify or retain data belonging to others.
- Do not conduct denial of service testing, social engineering, physical attacks, or spam.
- Do not publicly disclose the issue until we have confirmed remediation, or ninety days have passed from your report, whichever is earlier.
- Stop testing and report immediately if you encounter personal data.
5. Out of scope
- Reports from automated scanners without demonstrated exploitability.
- Missing best practice headers or configuration issues with no demonstrated security impact.
- Social engineering of our personnel, clients or vendors.
- Vulnerabilities in third party services we do not control.
- Reports requiring physical access to a device, or an already compromised device.
6. Rewards
We do not currently operate a paid bug bounty programme. We recognise valid reports with written acknowledgement and, with your consent, public credit.