Security & Vulnerability Disclosure
We run automated website audits and manage real client infrastructure, so we take security reports seriously and will always work with a good-faith researcher to understand and fix a real issue. This page is our security.txt-referenced disclosure policy: how to report a problem, what's in scope, and what you can expect from us.
How to report
Email hello@bitwisedesigns.com with a description of the issue, the steps to reproduce it, and any proof-of-concept detail that helps us confirm it quickly. We're a small team - a request/response transcript or a short screen recording is often more useful to us than a lengthy write-up. Please don't open a public GitHub issue or post about an unpatched vulnerability publicly before we've had a chance to respond.
What's in scope
- bitwisedesigns.com and its subpages (the site you're reading this on).
- ops.bitwisedesigns.com - our audit-report, client-progress, and webhook API endpoints.
- The free website audit tool.
- Our email-sending and outreach infrastructure, if you can demonstrate a real security impact (not just "I got an email").
What's out of scope
- Third-party services we use but don't control - Stripe, Google, Cloudflare, DigitalOcean, Instantly, Anthropic - please report those directly to the vendor.
- Denial-of-service or volumetric testing against any BitwiseDesigns property. Ask first if you need to test something that could affect availability.
- Social engineering, phishing, or physical-security attempts against us or our clients.
- Findings that require an already-compromised device, a rooted/jailbroken device, or physical access to someone's machine.
- Missing security headers, cookie flags, or rate-limit tuning with no demonstrated exploit - these are welcome as informational notes, but we triage confirmed-impact reports first.
- Vulnerabilities in a client's own website that we audited or fixed but that live outside our own infrastructure - report those to the site owner directly; we're happy to make an introduction if you let us know.
Safe harbor
If you make a good-faith effort to follow this policy while researching or reporting a vulnerability, we will not pursue legal action against you for that research, and we'll work with you to understand and resolve the issue quickly. This applies to testing you do against your own account/data or against publicly accessible parts of our infrastructure without degrading service for anyone else.
What to expect from us
- Acknowledgment within 3 business days of a report reaching hello@bitwisedesigns.com.
- An initial assessment - confirmed, needs more information, or out of scope - within 7 business days.
- A fix or mitigation for any confirmed issue, timed to its real-world severity rather than a fixed SLA, with a status update if it takes longer than a couple of weeks.
- Credit, if you'd like it, once a fix ships - we don't currently run a paid bug bounty program, but we'll happily name you here or in our blog as the reporter of a real, confirmed issue.
Contact
Security reports: hello@bitwisedesigns.com. For anything else, see our Privacy Policy or write to BitwiseDesigns (a service of Triton Agency LLC), PO Box 36874, 2191 Ebenezer Rd, Rock Hill, SC 29732.