Responsible disclosure

If you believe you have found a security vulnerability in a BoxBite Security system, we want to hear about it.

How to report

Email info@boxbite.io with enough detail to reproduce the issue: the affected endpoint, the steps taken and the impact you observed.

What we ask

  • Give us a reasonable opportunity to remediate before any public disclosure.
  • Do not access, modify or delete data belonging to anyone else.
  • Do not run denial-of-service tests or send automated high-volume traffic.
  • Stay within our systems; do not pivot to third-party services.

What we commit to

  • We acknowledge reports within three business days.
  • We keep you informed while we investigate and remediate.
  • We credit reporters who want to be named, once the issue is fixed.
  • We will not pursue legal action against researchers who follow this policy in good faith.

This policy covers BoxBite Security's own systems only. It is not authorisation to test any client environment.

Loading...
Back to top