SupplierClear

Vulnerability disclosure

# Vulnerability disclosure policy — SupplierClear (Bacenik)

**Effective:** 2026-07-23  
**Contact:** security@bacenik.com (also info@bacenik.com)

## Scope

In scope: SupplierClear's production web application and APIs, authentication, payment integrations, customer-facing collaboration features, and customer data handling.

Out of scope: social engineering of Bacenik staff, physical attacks, denial-of-service testing against shared infrastructure, and third-party provider vulnerabilities that should be reported to the relevant provider.

## Safe harbor

If you make a good-faith effort to avoid privacy violations, service degradation, and data destruction, Bacenik will not pursue legal action for security research that follows this policy.

## How to report

1. Email **security@bacenik.com** with a clear description, impact, and reproduction steps.
2. Do not access other customers’ data. Stop if you encounter PII beyond your own account.
3. Allow **10 business days** for initial acknowledgment and **90 days** before public disclosure (coordinated disclosure).

## What we ask

- No automated scanning that degrades production availability
- No ransomware, extortion, or public dumps of customer data
- Prefer proof-of-concept that demonstrates impact without exploiting beyond necessity

## Rewards

Bacenik may offer discretionary recognition for significant findings. This is **not** a paid bug-bounty program unless separately announced.

## Related

- Trust center: `/trust`
- Security contact: security@bacenik.com