Reported privately, fixed, then disclosed together

Found a security issue in Bugb? Tell us privately.

This policy covers vulnerabilities in Bugb’s own websites, services and products. It says how to report one, what you may test, and what we do in return.

Last updated . Looking for how Bugb reports vulnerabilities it finds in other organisations’ software? That’s our disclosure process.

How to report

Email security@bugb.report. Email is the reporting channel; we don’t take vulnerability reports through the contact forms, GitHub or Discord.

A useful report includes:

  • The affected product, website or service, with the URL or the version.
  • Steps to reproduce, from a clean start.
  • What an attacker could do with it, and to whom.
  • A proof of concept: a request, script or screenshots. Keep it to the minimum that shows the issue.
  • How to reach you, and the name you’d like us to use.

Don’t include other people’s personal data. If you came across some while testing, describe what kind of data it was and where, without copying it into the report.

Out of scope

  • Denial of service, and spam or high-volume automated testing.
  • Social engineering or phishing of Bugb staff or contractors.
  • Physical attacks on offices, people or equipment.
  • Services run by third parties, such as our hosting, payment, email or community providers. Report those to the provider.
  • Missing security headers or cookie flags with no demonstrated impact.
  • Self-XSS, and clickjacking on pages with no sensitive action.

Found a vulnerability in someone else’s software? That isn’t covered here, but we can help you disclose it.

Testing rules

  • Test in good faith, only to find and demonstrate a vulnerability.
  • Use accounts you own, or that the account holder has explicitly allowed you to use.
  • Don’t access, change or delete other users’ data. If you reach data that isn’t yours, stop there and report it.
  • Don’t degrade our services for anyone else.
  • Keep the details confidential until we’ve fixed the issue, or until we’ve agreed on a date to publish together.

What happens next

  1. We acknowledge your report within 2 business days, from a person, so you know it reached us.
  2. We triage it. We reproduce the issue, decide whether it’s a vulnerability and how severe it is, and tell you what we found within 7 business days of acknowledging it. If we need more from you, we’ll ask.
  3. We fix it as soon as we can, and keep you updated while we do.
  4. We disclose it together. Once a fix is available, we agree with you when and how the issue is published. If we haven't agreed a date, please give us 90 days from your report before publishing.

No bug bounty

We don’t run a paid bug bounty programme at the moment, and we don’t pay for reports. With your permission, we'll credit you by name in the advisory or release notes for the fix.

Safe harbour

If you make a good-faith effort to follow this policy, we consider your research to be authorised, and:

  • We won’t take or support legal action against you for it, including for accidental, good-faith breaches of this policy.
  • We won’t bring a claim against you for working around technical controls as part of that research.
  • We waive the restrictions in our terms that would otherwise prevent that research, to the limited extent needed.

You must still comply with the law. If a third party takes legal action against you over research that followed this policy, we’ll make it known that you acted in line with it. This safe harbour covers only Bugb’s own systems and products; we can’t authorise testing of anyone else’s.

If you’re unsure whether something you want to do is covered, ask us at security@bugb.report before you go further.