Security Testing Policy
Last updated: 6 April 2026
1. Introduction
Be Bitwise welcomes responsible security research that helps keep the platform and its users safe. We recognise the valuable contribution that security researchers make to the security community and we are committed to working with them in good faith.
All security testing of the Be Bitwise platform must be conducted in accordance with this policy. By conducting security testing, you agree to comply with the rules set out below.
2. Scope
This policy applies to the Be Bitwise web application at bebitwise.io, the link shortening service at bbw.gg, and their associated API endpoints.
Only the production web applications and their APIs are in scope unless otherwise agreed in writing.
3. Out of Scope
The following are expressly out of scope:
- Third-party services used by Be Bitwise (such as Supabase, Resend, and Cloudflare). These services are governed by their own security policies and should not be tested through Be Bitwise.
- Social engineering attacks against Be Bitwise staff, users, or contributors.
- Physical attacks against Be Bitwise infrastructure or personnel.
- Denial-of-service (DoS or DDoS) attacks, or any testing intended to degrade service availability.
- Automated scanning tools run at volumes that could degrade service performance or availability.
- Attacks against underlying infrastructure (hosting, DNS, CDN) that could cause real damage or service outages.
4. Rules of Engagement
When conducting security testing, you must adhere to the following rules:
- Do not access, modify, or delete other users’ data.
- Do not perform destructive actions against the platform or its data.
- Do not use automated scanners or fuzzing tools at high volume. Rate-limit your testing to avoid any disruption to the service.
- Do not attempt denial of service in any form.
- Do not exploit vulnerabilities beyond what is minimally necessary to demonstrate their existence. Proof of concept should be the goal, not full exploitation.
- Do not exfiltrate data. If you encounter sensitive data during testing, stop immediately and report the issue.
- If you accidentally access another user’s data or sensitive information, stop testing immediately, do not store or share the data, and report the issue to us.
- Act in good faith at all times.
5. Reporting Vulnerabilities
Please report vulnerabilities by e-mail to security@bebitwise.io.
Your report should include:
- A clear description of the vulnerability.
- Step-by-step instructions to reproduce the issue.
- An assessment of the potential impact.
- Any supporting evidence, such as screenshots, logs, or proof-of-concept code.
Please do not include sensitive data (such as other users’ personal information) in your report beyond what is necessary to describe the issue.
6. Our Response Commitment
When you report a vulnerability in accordance with this policy, we commit to:
- Acknowledging your report within 3 business days.
- Providing an initial assessment and status update within 10 business days.
- Aiming to remediate confirmed vulnerabilities within 30 days, depending on severity and complexity.
- Keeping you informed of progress where possible.
7. Disclosure
We ask that you give Be Bitwise reasonable time to investigate and remediate a reported vulnerability before making any public disclosure. We request a minimum of 90 days from the date of your initial report before any public disclosure.
We will work with you to agree on an appropriate disclosure timeline. If you believe a vulnerability poses an immediate risk to users, please make this clear in your report so that we can prioritise accordingly.
8. Recognition
Researchers who report valid, previously unreported vulnerabilities may be credited on a Hall of Fame page on the Be Bitwise website, with their permission.
There is no monetary bounty programme at this time, though this may be introduced in the future. Recognition is at the sole discretion of Be Bitwise.
9. Safe Harbour
Be Bitwise will not pursue legal action against security researchers who conduct testing in good faith and in compliance with this policy. We consider security research conducted in accordance with this policy to be authorised activity and will not initiate legal proceedings under the Computer Misuse Act 1990 or equivalent legislation.
This safe harbour applies only to legal claims that Be Bitwise could bring. It does not bind other parties. If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will make reasonable efforts to make it known that your actions were authorised under this policy.
10. What This Policy Does Not Authorise
For the avoidance of doubt, this policy does not authorise:
- Any activity that could damage the platform, its infrastructure, or its users.
- Attacks against third-party services, even those used by Be Bitwise.
- The storage, sharing, or public disclosure of any user data encountered during testing.
- Any activity that falls outside the scope defined in this policy.
Violation of the rules set out in this policy may result in account termination and referral to law enforcement. This policy does not constitute a blanket authorisation to test; it sets out the conditions under which testing is permitted.