Vulnerability disclosure
# Vulnerability disclosure policy — SupplierClear (Bacenik)
**Effective:** 2026-07-23
**Contact:** security@bacenik.com (also info@bacenik.com)
## Scope
In scope: SupplierClear's production web application and APIs, authentication, payment integrations, customer-facing collaboration features, and customer data handling.
Out of scope: social engineering of Bacenik staff, physical attacks, denial-of-service testing against shared infrastructure, and third-party provider vulnerabilities that should be reported to the relevant provider.
## Safe harbor
If you make a good-faith effort to avoid privacy violations, service degradation, and data destruction, Bacenik will not pursue legal action for security research that follows this policy.
## How to report
1. Email **security@bacenik.com** with a clear description, impact, and reproduction steps.
2. Do not access other customers’ data. Stop if you encounter PII beyond your own account.
3. Allow **10 business days** for initial acknowledgment and **90 days** before public disclosure (coordinated disclosure).
## What we ask
- No automated scanning that degrades production availability
- No ransomware, extortion, or public dumps of customer data
- Prefer proof-of-concept that demonstrates impact without exploiting beyond necessity
## Rewards
Bacenik may offer discretionary recognition for significant findings. This is **not** a paid bug-bounty program unless separately announced.
## Related
- Trust center: `/trust`
- Security contact: security@bacenik.com