This policy describes how bcsec handles vulnerabilities discovered through its own security research, and how vulnerabilities affecting bcsec are reported to us.
Send reports to [email protected]. Please include affected asset or service, affected version or configuration, technical description, reproduction steps, and observed impact. We respond within ten working days.
We will not pursue legal action against reporters who act in good faith, avoid privacy violations and service disruption, and do not access, modify, or exfiltrate data belonging to third parties.
When our research identifies a vulnerability in a third-party product or service, we follow coordinated disclosure.
Notification. We contact the vendor or provider through its published security contact, or through its national CSIRT where no such contact exists.
Disclosure timeline. We publish 90 days after the initial notification. The period may be extended where the vendor is actively working on a fix and keeps us informed of progress.
Reduced timeline. We may publish before 90 days where the vulnerability is already being actively exploited, where the vendor is unreachable or does not engage after repeated attempts, or where the issue is already public through other channels. Any reduction is stated in the advisory, with its reason.
Disputed findings. Where a vendor confirms the observed behaviour but disputes that it constitutes a vulnerability, bcsec publishes its own record and documents the vendor's position alongside our own assessment. Readers are given both, and can form their own view.
Credit. We credit all researchers who contributed to a finding, and we ask that assigning authorities do the same.
Advisories are published on bcsec.io and, where applicable, through public disclosure lists.
Vulnerability records in GCVE-BCP-05 format are published at the endpoint declared in the GCVE directory. The endpoint address is listed on this page once allocated.
Where a CVE identifier has been assigned, it is referenced in the record. Where a record relates to an identifier assigned by another authority, a cross-reference is included.
Replies may come from the alternate address [email protected]. Reports should always be sent to [email protected].