Security Policy

Bitsmiths is committed to maintaining the security of our systems and protecting our clients' data. We appreciate the security community's efforts in responsibly disclosing vulnerabilities.

Reporting Security Vulnerabilities

How to report security issues to our team

If you discover a security vulnerability in any of our systems, services, or software, please report it to us immediately. We take all security reports seriously and will respond promptly.

Contact Information:

What to Include in Your Report

Please provide as much detail as possible to help us understand and reproduce the issue

  • Description: A clear description of the vulnerability and its potential impact
  • Steps to Reproduce: Detailed steps to reproduce the vulnerability
  • Proof of Concept: Screenshots, videos, or code samples (if applicable)
  • Environment: System versions, browsers, or platforms affected
  • Severity Assessment: Your assessment of the vulnerability's impact

Our Response Process

Timeline and process for handling security reports

Initial Response: 24-48 hours

We will acknowledge receipt of your report and provide an initial assessment

Investigation: 3-7 business days

Our security team will investigate and validate the reported vulnerability

Resolution: Timeline varies

We will work to resolve the issue as quickly as possible, with timeline depending on complexity

Follow-up: After resolution

We will notify you when the issue has been resolved and thank you for your responsible disclosure

Responsible Disclosure Guidelines

Guidelines for ethical security research

To protect our clients and systems, we ask that security researchers follow these guidelines:

✅ Please Do:

  • • Report vulnerabilities as soon as possible
  • • Use only test accounts or your own accounts
  • • Respect user privacy and data
  • • Wait for our response before public disclosure
  • • Provide detailed reproduction steps

❌ Please Don't:

  • • Access or modify user data without permission
  • • Perform denial of service attacks
  • • Share vulnerabilities publicly before resolution
  • • Use automated vulnerability scanners
  • • Attempt social engineering attacks

Our Security Commitment

At Bitsmiths, security is fundamental to our software development process. We implement security best practices throughout our development lifecycle and continuously monitor our systems for potential threats.

We are grateful to the security research community for their efforts in keeping the internet safe and appreciate responsible disclosure of security vulnerabilities.

This security policy was last updated on August 26, 2025