Home
Resources
BlogBest Practices
AboutContact
Book a demoLogin

We value the work of security researchers. If you believe you have found a vulnerability in Bayescase, please report it to us. This policy explains how, and what you can expect in return.

1. Scope

  • bayescase.com (including www.bayescase.com)
  • app.bayescase.com
  • api.bayescase.com

2. How to report

Email security@bayescase.com with:

  • a description of the vulnerability,
  • steps to reproduce it,
  • its impact, as you understand it.

Don't include customer data beyond what is needed to demonstrate the issue.

3. Our commitments

  • We acknowledge your report within 2 business days.
  • We keep you informed while we investigate and fix.
  • We aim to fix critical issues within 7 days and high-severity issues within 30 days.
  • If you wish, we credit you once the issue is fixed.

4. Rules

  • No denial-of-service or load testing.
  • No social engineering or phishing.
  • Don't access or change other users' data. If you gain access to data that isn't yours, stop and report it.
  • Test only with your own accounts.
  • Give us reasonable time to fix the issue (up to 90 days) before disclosing it publicly.

5. Safe harbor

We won't take legal action against good-faith research that follows these rules.

6. No bug bounty

We don't run a bug bounty program and don't pay for reports.