Coordinated disclosure for Bitscaled-operated systems. Unauthorized testing of customer environments is prohibited. There is no paid bug bounty.
Version: VDP-v1.0 • Effective Date: August 17, 2026
Bitscaled LLC welcomes good-faith reports of security vulnerabilities in systems we operate. This policy describes scope, how to report, and the safe harbor we offer researchers who follow it. It is a coordinated disclosure policy, not a paid bug bounty.
You may research and report vulnerabilities in Bitscaled-operated properties, including:
Use only accounts you own or that we explicitly authorize. Do not access another organization's Workspace data.
The following are not authorized and are not covered by safe harbor:
Email a clear report to security@bitscaled.tech and copy legal@bitscaled.tech. Include the affected URL or host, a description of the issue, steps to reproduce, impact, and any proof that does not include extra personal data.
Encrypted email is optional. If you need a PGP key, request one from security@bitscaled.tech. We do not publish a fingerprint on this page.
Give us a reasonable time to investigate and fix before public disclosure. We will try to acknowledge receipt. We may ask follow-up questions. Do not demand payment as a condition of disclosing a vulnerability.
If you conduct research in good faith, stay in scope, follow this policy, and do not exploit a finding beyond demonstration, Bitscaled will not bring a civil action against you or refer the matter to law enforcement for that research. We cannot bind third parties or prosecutors. If a third party takes action, we will make it known that you followed this policy.
Safe harbor does not apply to out-of-scope testing, extortion, public disclosure made to pressure payment, or harm to clients or other users.
Bitscaled does not operate a paid bug bounty program. We may thank researchers who report in-scope issues. We do not offer payment, swag with a stated value, or points unless we expressly agree in writing before the research begins. Absence of a bounty does not reduce the expectation that you follow this policy.
Security: security@bitscaled.tech. Legal: legal@bitscaled.tech.
Related policies that explain how we operate, protect your data, and provide our services transparently.
How we handle website, account, newsletter, VaultTools, and managed-service data.
Read Privacy PolicyThe rules for using our website, client portal, public tools, and managed services.
Read Terms of ServiceWhat you may and may not do on our website, Client Workspace, public tools, and managed environments.
Read Acceptable Use PolicyNamed cookies, localStorage consent, and how to change analytics preferences.
Read Cookies PolicyProcessor terms for Client Data in managed services and hosted Workspace content.
Read Data Processing AgreementVendors that may process Website Data or Client Data, including optional tools.
Read SubprocessorsCopyright notices, counter-notices, and designated agent contact.
Read DMCA PolicyHow to report security issues in Bitscaled-operated systems in good faith.
Read Vulnerability DisclosureThese documents explain how we handle privacy, terms, cookies, data processing, and acceptable use without implying certifications outside the written policies.
If you have questions about any of our legal documents or need clarification on our policies, our legal team is here to help.