Security Policy
Bitsmiths is committed to maintaining the security of our systems and protecting our clients' data. We appreciate the security community's efforts in responsibly disclosing vulnerabilities.
Reporting Security Vulnerabilities
How to report security issues to our team
If you discover a security vulnerability in any of our systems, services, or software, please report it to us immediately. We take all security reports seriously and will respond promptly.
Contact Information:
- Email: info@bitsmiths.co.za
- Subject Line: [SECURITY] - Brief description of the issue
- Contact: https://bitsmiths.co.za/contact/
What to Include in Your Report
Please provide as much detail as possible to help us understand and reproduce the issue
- Description: A clear description of the vulnerability and its potential impact
- Steps to Reproduce: Detailed steps to reproduce the vulnerability
- Proof of Concept: Screenshots, videos, or code samples (if applicable)
- Environment: System versions, browsers, or platforms affected
- Severity Assessment: Your assessment of the vulnerability's impact
Our Response Process
Timeline and process for handling security reports
Initial Response: 24-48 hours
We will acknowledge receipt of your report and provide an initial assessment
Investigation: 3-7 business days
Our security team will investigate and validate the reported vulnerability
Resolution: Timeline varies
We will work to resolve the issue as quickly as possible, with timeline depending on complexity
Follow-up: After resolution
We will notify you when the issue has been resolved and thank you for your responsible disclosure
Responsible Disclosure Guidelines
Guidelines for ethical security research
To protect our clients and systems, we ask that security researchers follow these guidelines:
✅ Please Do:
- • Report vulnerabilities as soon as possible
- • Use only test accounts or your own accounts
- • Respect user privacy and data
- • Wait for our response before public disclosure
- • Provide detailed reproduction steps
❌ Please Don't:
- • Access or modify user data without permission
- • Perform denial of service attacks
- • Share vulnerabilities publicly before resolution
- • Use automated vulnerability scanners
- • Attempt social engineering attacks
Our Security Commitment
At Bitsmiths, security is fundamental to our software development process. We implement security best practices throughout our development lifecycle and continuously monitor our systems for potential threats.
We are grateful to the security research community for their efforts in keeping the internet safe and appreciate responsible disclosure of security vulnerabilities.
This security policy was last updated on August 26, 2025