HomePolicies

Reporting a security problem

How to tell us about a vulnerability, what we will do, and what we ask of you.

Tell us

Write to security@buysidefintech.com. Include what you found, where, and enough detail for us to reproduce it. This address is also published at /.well-known/security.txt, in the format defined by RFC 9116.

What we will do

We will not take legal action against anyone who reports a problem in good faith under this policy, and we will not ask you to sign anything before we will listen.

What we ask of you

Out of scope

Reports generated by a scanner with no working proof; missing headers with no exploitable consequence; the absence of a rate limit on something harmless; and anything requiring a person to already have your device or your password. We will read them, but we may only say thank you.

There is no reward

We do not run a bug bounty and we are not going to pretend otherwise. What we offer is a quick answer, a fix, and credit if you want it.