Security

Security And Responsible Disclosure

How to report security concerns about BrighouseSec, and the boundaries used for BrighouseSec snapshot work.

Security contact: sales@brighousesec.com

Reporting A Security Issue

If you believe you have found a security issue affecting BrighouseSec, please report it to sales@brighousesec.com. Include a clear summary, affected URL or system, steps to reproduce where safe, and any relevant timestamps.

Responsible Disclosure Guidance

Please act in good faith and avoid actions that could harm BrighouseSec, customers, visitors or third parties. Do not access, modify, delete, exfiltrate or disrupt data. Do not access third-party data or continue testing after you have enough information to report the issue.

Out Of Scope Activity

  • Social engineering, phishing, spam or physical attacks.
  • DDoS, resource exhaustion or destructive testing.
  • Accessing, copying, modifying or deleting data that is not yours.
  • Testing third-party services, customers, partners or infrastructure without permission.

Good-Faith Reports

BrighouseSec will aim to handle good-faith reports fairly where the researcher follows this policy, avoids privacy harm, avoids disruption and reports promptly. This is not permission to break the law or access systems without authorisation.

Scanner Safety Summary

  • Passive external checks only.
  • Authorised domains only.
  • No exploitation.
  • No brute force.
  • No credential testing.
  • No destructive testing.
  • No port scanning unless separately agreed in writing.