Security and Vulnerability Disclosure Policy

We take the security of our systems seriously, and we would rather hear about a problem from you than discover it another way.

This policy explains what you may test, how to report what you find, what we commit to in return, and — importantly — that we will not pursue legal action against you for good-faith research that follows this policy.

If you are unsure whether something is in scope, ask us at security@bit.foo before you start. We would rather have that conversation up front.

Scope

In scope

  • bit.foo and its subdomains that we operate
  • my.bit.foo — our client portal
  • Our virtual server control panel
  • status.bit.foo
  • Our own network infrastructure and the IP address space we announce, subject to the limits in “Rules of engagement” below

A note on our portal and control panel. These run third-party software on our own infrastructure. Our configuration and deployment are in scope. If you find a vulnerability in the underlying software itself rather than in how we have deployed it, please report it to us and to the vendor — they can fix it for everyone.

Out of scope

We cannot authorise testing of systems we do not control, and we will not pretend otherwise. The following are out of scope, and testing them is not covered by this policy:

  • Our customers' servers, websites, applications, and data. These belong to our customers. Testing them without their permission is an attack on a third party, regardless of the fact that they run on our network
  • Our shared hosting platform infrastructure, which is operated by a partner. We have no authority to authorise testing of it
  • Third-party services we use — payment processing, domain registration, certificate issuance, and similar. Report those to the provider concerned
  • Any system not listed as in scope

Authorisation and safe harbour

Rules of engagement

Please do:

  • Use only the minimum access necessary to demonstrate a vulnerability
  • Stop as soon as you have confirmed a finding, and report it
  • Use your own test account or data wherever possible — ask us for one, see below
  • Give us a reasonable opportunity to fix the issue before telling anyone else

Please do not:

  • Access, modify, delete, or exfiltrate data that is not yours. If you encounter customer data, stop immediately and tell us what you saw so we can assess it
  • Do anything that degrades or interrupts our services — no denial of service, no volumetric testing, no resource exhaustion
  • Run automated scanners at a rate that affects availability
  • Attempt to move laterally, establish persistence, or pivot to customer systems
  • Attempt social engineering of our staff, our partners, or our customers
  • Attempt physical access to any facility
  • Send spam or phishing, even as a test
  • Demand payment in exchange for disclosure, or threaten publication to obtain one

Findings we consider out of scope

These are usually reported by automated tools and we generally cannot act on them without a demonstrated impact:

  • Missing security headers with no demonstrated exploit
  • SPF, DKIM, or DMARC configuration observations
  • Self-XSS
  • Clickjacking on pages with no sensitive action
  • Missing rate limiting on endpoints that do not handle authentication
  • Version disclosure or outdated software without a working exploit
  • Reports produced by a scanner and submitted without validation
  • Best-practice recommendations with no security impact

If you believe one of these is genuinely exploitable in our environment, show us and we will look. The list describes what we usually cannot use, not a refusal to consider.

How to report

Email security@bit.foo.

Please include:

  • A description of the vulnerability and why it matters
  • The affected system, URL, or endpoint
  • Steps to reproduce it, in enough detail that we can follow them
  • A proof of concept, if you can produce one safely
  • Any output, screenshots, or logs that help
  • How you would like to be credited, if at all

Report in English where you can. We will do our best with anything else, but translation slows us down.

What we commit to

  • We will acknowledge your report within 3 business days.
  • We will tell you whether we have been able to reproduce it, and what we intend to do
  • We will keep you updated as we work on it, and tell you when it is fixed
  • We will work with you on disclosure timing rather than dictating it
  • We will not ask you to sign a non-disclosure agreement as a condition of reporting, and we will not ask you to stay silent indefinitely

Test accounts

We will provide a test account on request. Email security@bit.foo and tell us what you want to look at.

We would much rather you tested against an account we gave you than against a real customer's.

Recognition

We do not run a bug bounty programme and we do not offer a schedule of payments.

We will credit you by name in any advisory we publish, if you would like us to — and equally we will not, if you would prefer to stay anonymous. Just tell us.

Where a report is genuinely useful to us, we may offer account credit as a thank you. This is entirely at our discretion, there is no schedule, and no report entitles you to it. Any credit is subject to the terms in our Refund and Cancellation Policy — it can be used against our services, and it is not transferable or exchangeable for cash.

Coordinated disclosure

We ask that you give us a reasonable opportunity to fix an issue before publishing it. As a default we suggest 90 days, and we are happy to discuss a different timeline where the circumstances warrant it.

We will not demand indefinite silence. If we are taking too long, tell us — that is a fair thing for you to raise, and we would rather hear it from you than read it elsewhere.

If you intend to request a CVE, tell us and we will help.