Security Acknowledgments
Responsible-disclosure program for the BizKitHub platform — how to report vulnerabilities, our response process, and recognition of security researchers who help keep the platform safe.
We recognize and thank security researchers who help keep the BizKitHub platform secure through responsible disclosure of security vulnerabilities.
Responsible security research. We appreciate the security community's efforts to keep our platform safe. If you discover a security vulnerability, please report it responsibly through our security contact.
Reporting guidelines
- Responsible disclosure. Report vulnerabilities privately before public disclosure.
- No harm policy. Do not access, modify, or delete user data.
- Timely reporting. Report findings as soon as possible after discovery.
- Good faith research. Conduct security research in good faith and within legal boundaries.
How to report
Security contact.
- Email: jan@barasek.com
- Subject:
[SECURITY] Vulnerability Report - For sensitive reports, use our PGP key for encryption.
Include in your report:
- Detailed description of the vulnerability
- Steps to reproduce the issue
- Potential impact assessment
- Proof of concept (if applicable)
- Your contact information for follow-up
Our response process
- Report received. We acknowledge receipt within 24 hours.
- Investigation. Initial assessment within 72 hours.
- Resolution. Fix deployed based on severity.
- Recognition. Public acknowledgment (if desired).
Hall of Fame
| Researcher | Date | Severity | Description | Status | Reward |
|---|---|---|---|---|---|
| Security Researcher | 2024-12-15 | Medium | Reported potential XSS vulnerability in user input validation | Fixed | Recognition |
| Anonymous Researcher | 2024-11-28 | Low | Information disclosure in error messages | Fixed | Recognition |
| Ethical Hacker | 2024-10-12 | High | Authentication bypass in legacy API endpoint | Fixed | Recognition + Bounty |
Important notice
Please do not test vulnerabilities on production systems. Contact us first to discuss safe testing environments if needed.
Legal protection
We will not pursue legal action against researchers who follow responsible disclosure guidelines and act in good faith.
Found a security issue?
We appreciate responsible disclosure of security vulnerabilities. Contact our security team at jan@barasek.com — subject [SECURITY] Vulnerability Report — for any security-related concerns. You can also refer to the machine-readable security.txt.