Responsible Disclosure Policy
Last updated: August 2026
We build security, so we welcome it in return. If you believe you have found a security vulnerability in BugCanary's own website or infrastructure, we'd like to hear from you.
Scope
This policy covers bugcanary.com and systems we own and operate. It does not authorize testing of our clients or any third party.
Safe harbor
If you make a good-faith effort to comply with this policy during your research, we will consider your testing to be authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue or support legal action against you for accidental, good-faith violations of this policy.
Ground rules
- Stay within scope; only test systems we own.
- Do not access, modify, or exfiltrate data that isn't yours — use the minimum needed to demonstrate the issue.
- No denial-of-service, spam, social engineering, or physical attacks.
- Give us reasonable time to remediate before any public disclosure, and coordinate disclosure with us.
How to report
Email contact@bugcanary.com with a clear description, steps to reproduce, and impact. We aim to acknowledge reports promptly. We don't currently run a paid bounty, but we genuinely appreciate and credit responsible reports.