BELA
✦ Ask BELA Sign in
Home › Responsible Disclosure
Responsible disclosure

Found a vulnerability? We want to hear from you

We value the security community. If you believe you have found a security issue in BELA, this page explains how to report it and what you can expect from us.

How to report

  1. 01
    Email our security team

    Send details to our security contact. Include steps to reproduce, affected URLs and any proof-of-concept. One clear report is worth more than ten vague ones.

  2. 02
    Give us time to respond

    We will acknowledge your report and keep you updated as we investigate and remediate. Please do not disclose publicly until we have had a reasonable chance to fix the issue.

  3. 03
    We fix and credit

    Once resolved, we are happy to credit your contribution if you wish. We treat good-faith researchers as partners, not adversaries.

Safe harbour

Acting in good faith under this policy, you can expect:

We will not pursue legal action for good-faith research within scope
Our commitment
We will work with you to understand and resolve the issue quickly
Our commitment
We will recognise your contribution where you want us to
Our commitment

Scope and expectations

Please test only against your own account and data. Do not access, modify or delete other users’ data, degrade the service, or run automated scans that disrupt availability. Social engineering, physical attacks and denial of service are out of scope.

We do not currently run a paid bug-bounty programme. We will always acknowledge valid reports and credit researchers who wish to be named.

Report a security issue

Prefer to reach a human first? Our team will route you to security.