Reporting a security problem
How to tell us about a vulnerability, what we will do, and what we ask of you.
Tell us
Write to security@buysidefintech.com. Include what you found, where, and enough detail for us to reproduce it. This address is also published at /.well-known/security.txt, in the format defined by RFC 9116.
What we will do
- Acknowledge within two working days.
- Tell you whether we can reproduce it, and what we judge its severity to be.
- Fix what needs fixing, and tell you when it is done.
- Credit you if you would like it. Say so and how you would like to be named; say nothing and we will keep you out of it.
We will not take legal action against anyone who reports a problem in good faith under this policy, and we will not ask you to sign anything before we will listen.
What we ask of you
- Give us a reasonable chance to fix it before you tell anybody else.
- Do not access, change or keep anybody else’s data. If you reach data that is not yours, stop, and tell us what you reached rather than how much of it you could take.
- No denial of service, no load testing, no spam, and nothing physical or social.
- Test against your own account. If you need one, ask and we will make you one.
Out of scope
Reports generated by a scanner with no working proof; missing headers with no exploitable consequence; the absence of a rate limit on something harmless; and anything requiring a person to already have your device or your password. We will read them, but we may only say thank you.
There is no reward
We do not run a bug bounty and we are not going to pretend otherwise. What we offer is a quick answer, a fix, and credit if you want it.