Security

Responsible Disclosure Policy

Last updated: July 7, 2026 | Reports: [email protected]

1. We want to hear from you

BCINexus stores research data people care deeply about. If you find a security vulnerability, we would much rather hear about it from you than discover it in an incident report. This policy tells you how to report responsibly and what you can expect from us in return. It applies to bcinexus.xyz, the BCINexus APIs, and the BCILattice desktop application's cloud features.

2. How to report

Email [email protected] with: - A description of the vulnerability and its impact - Steps to reproduce (proof-of-concept code or requests are welcome) - The affected URL, endpoint, or component - Your contact details, and whether you'd like public credit if we publish an advisory We aim to acknowledge reports within 5 business days and to keep you informed while we investigate and fix the issue.

3. The rules

To stay within this policy while researching: - Do not access, modify, or delete data that isn't yours. If a proof-of-concept exposes another user's data, stop immediately and report - Do not degrade the service — no denial-of-service testing, resource exhaustion, or spam - No social engineering of BCINexus staff or users, and no physical attacks - Use test accounts you created; don't pivot into other users' accounts - Give us a reasonable opportunity to fix the issue before any public disclosure - Don't demand payment as a condition of disclosure

4. What we promise

If you follow this policy in good faith, we will not initiate legal action against you for your research, and we will work with you rather than against you. We currently do not run a paid bug-bounty program. We do offer public credit in advisories and release notes for valid reports, if you want it.

5. Out of scope

- Findings from automated scanners with no demonstrated impact - Missing security headers or best-practice flags without an exploitable consequence - Vulnerabilities in third-party services we use (report those to the vendor — but tell us too if BCINexus data is affected) - Issues requiring physical access to a user's unlocked device - Social engineering, phishing simulations, and physical security testing