Do not test without written permission
Do not scan, exploit, access data, disrupt service, use social engineering or perform any security testing unless BugsBurner has provided explicit written authorization and scope.
Report a suspected issue
Email support@bugsburnertech.com with the affected URL, a clear description, observed impact, reproduction information that does not expose sensitive data, and a safe way to contact you.
Protect people and data
- Stop immediately if you encounter personal, confidential or client information.
- Do not download, alter, retain or publicly disclose data.
- Do not demand payment, threaten disclosure or contact clients or employees.
- Give us reasonable time to investigate before any coordinated disclosure discussion.
What to expect
We aim to acknowledge useful reports and assess them based on risk. Response timing, remediation and any recognition are determined case by case. Submission does not create a contract, employment relationship, reward entitlement or safe-harbour commitment.
Client systems
This policy covers only systems controlled by BugsBurner. It never authorizes testing of client, partner, employee, provider or third-party systems. Report issues affecting those organisations through their own published channels.
For authorized engagements
Client security work is governed by separate written scope, authorization, rules of engagement and reporting procedures. Website language such as “authorized cybersecurity” is not public permission to test.
