Security & Vulnerability Disclosure

We run automated website audits and manage real client infrastructure, so we take security reports seriously and will always work with a good-faith researcher to understand and fix a real issue. This page is our security.txt-referenced disclosure policy: how to report a problem, what's in scope, and what you can expect from us.

How to report

Email hello@bitwisedesigns.com with a description of the issue, the steps to reproduce it, and any proof-of-concept detail that helps us confirm it quickly. We're a small team - a request/response transcript or a short screen recording is often more useful to us than a lengthy write-up. Please don't open a public GitHub issue or post about an unpatched vulnerability publicly before we've had a chance to respond.

What's in scope

What's out of scope

Safe harbor

If you make a good-faith effort to follow this policy while researching or reporting a vulnerability, we will not pursue legal action against you for that research, and we'll work with you to understand and resolve the issue quickly. This applies to testing you do against your own account/data or against publicly accessible parts of our infrastructure without degrading service for anyone else.

What to expect from us

Contact

Security reports: hello@bitwisedesigns.com. For anything else, see our Privacy Policy or write to BitwiseDesigns (a service of Triton Agency LLC), PO Box 36874, 2191 Ebenezer Rd, Rock Hill, SC 29732.