Bugloud · Security
Responsible Disclosure Policy
How to report a security vulnerability in Bugloud’s own platform, the rules of engagement, our commitments, and the safe harbor we offer to good-faith researchers.
Version 3.1 · Effective 2023 · Last updated 2026
1. Our Commitment
Bugloud — the security-testing platform operated by Exordium, of which Bugloud is a product — takes the security of its platform and its users seriously. We welcome good-faith security research and are committed to working with researchers to verify, reproduce and fix legitimate reported vulnerabilities. This aligns with ISO/IEC 29147 (disclosure) and 30111 (handling).
This policy tells you which systems you may test, how to test them, how to report to us, what you can expect from us in return, and the legal safe harbor we offer.
2. Scope — In-Scope Assets
This policy authorises good-faith testing of the following assets, which Bugloud owns, operates or maintains:
- bugloud.com
- Bugloud API endpoints
3. Out of Scope
The following are not covered by this policy, and testing them is not authorised:
- Any system, domain or asset not listed in Section 2, including third-party services and vendors we use (for example Stripe, hosting, email and analytics providers).
- The systems of Companies that run Programs on Bugloud — those are governed by each Company’s own Program Brief, not this policy.
- Physical security, offices, and staff or contractors.
- Social engineering (phishing, vishing, smishing) and attacks on end-users.
- Denial-of-service, volumetric or resource-exhaustion attacks.
- Findings with no realistic security impact (see Section 5).
4. Rules of Engagement
When testing in-scope assets, you must:
- Minimise harm — avoid privacy violations, service disruption, data destruction and degradation of the experience for other users.
- Access only the minimum data needed to demonstrate a proof of concept; do not exfiltrate, store or share real user data.
- Stop and report immediately if you encounter personal, financial or other sensitive data, and do not access it further. Mere acquisition of such data can be an offence (Decree-Law 34/2021, Arts. 6–8).
- Use test accounts you own, or accounts you have explicit permission to use; do not interact with other people’s accounts.
- Not perform denial-of-service, social-engineering, physical, or automated high-volume scanning that could degrade service.
- Not pivot into out-of-scope systems, establish persistence, or install backdoors or miners.
- Not use IP-spoofing or anonymisation to conceal wrongdoing (Decree-Law 34/2021, Art. 10).
- Never extort or withhold a finding pending payment; report through our Official Channel only.
- Comply with all applicable laws, and not publicly disclose a vulnerability before we have fixed it and agreed disclosure.
5. What to Report / What Not to Report
We want to hear about
- Authentication and authorization flaws (e.g. IDOR, privilege escalation, broken access control).
- Injection (SQL, command, template), remote code execution.
- Sensitive data exposure and exposed secrets or credentials.
- Server-side request forgery, business-logic flaws, and payment/tenancy isolation issues.
- Cross-site scripting and cross-site request forgery with demonstrated impact.
Usually not eligible (unless you can show real impact)
- Missing security headers, cookie flags, or best-practice/informational findings without a working proof of concept.
- Self-XSS; clickjacking on pages with no sensitive action; missing rate limiting alone.
- Reports from automated tools without validation; outdated-library reports without a demonstrated exploit.
- Denial-of-service, social-engineering and physical findings.
6. Safe Harbor
Authorization. We authorise good-faith security research conducted in accordance with this policy on the in-scope assets in Section 2. To the extent we are legally entitled to do so, we consider such access to be authorized under UAE Federal Decree-Law No. 34 of 2021, and not a breach of our Terms of Service or Acceptable Use Policy — we waive those restrictions to the limited extent needed for the research.
We will not pursue you. For accidental, good-faith violations of this policy, we will not initiate or support a civil claim or file a criminal complaint against you, and if a third party brings an action against you for conduct that complied with this policy, we will take steps to make your authorization known.
Limits (important). This policy is not a waiver of, and cannot override, UAE criminal law. It does not bind the UAE Public Prosecution or any government authority and cannot guarantee against criminal investigation or prosecution. It authorises testing only of assets Bugloud owns or controls and listed in Section 2 — never government, financial or third-party systems.
When in doubt, ask first. If you are unsure whether an action is authorised or consistent with this policy, contact us through the Official Channel (Section 7) before proceeding. Safe harbor does not apply to conduct that is malicious, out of scope, or otherwise inconsistent with this policy.
7. How to Report
Official Channel. Send your report to [email protected].
Include: a clear description of the vulnerability; the affected asset/URL; step-by-step reproduction; a proof of concept; and an assessment of impact. Do not include more third-party personal data than necessary.
Anonymity. You may report anonymously. If you would like acknowledgement or credit, tell us how to contact you and how you wish to be named.
8. Our Response & Timelines
| Stage | Our target |
|---|---|
| Acknowledge your report | Within 3 business days (if you gave contact details) |
| Initial assessment / triage | Within 10 business days |
| Status updates | Ongoing; we will keep you informed of progress |
| Remediation | Prioritised by severity (target: critical issues within 30 days, within operational constraints) |
9. Coordinated Disclosure
Please keep vulnerability details confidential until we have remediated and agreed timing with you. We aim to coordinate public disclosure by mutual agreement, with a backstop of 90 days from acknowledgement.
Immediate protective steps are permitted where there is evidence of active exploitation; contact us at once in that case.
10. Recognition
We appreciate researchers who help improve our security. With your permission, we will recognise your contribution on the Bugloud Pioneers Board. If you prefer to remain anonymous, we will respect that.
This is a disclosure policy for Bugloud’s own assets and does not guarantee a monetary reward. Any bounty is discretionary. Paid opportunities are offered through Programs that Companies run on the Platform.
11. Relationship to Our Terms & Changes
For good-faith research consistent with this policy, this policy prevails over any conflicting restriction in our Terms of Service or Acceptable Use Policy, to the limited extent described in Section 6. We may update this policy; the current version governs research conducted after it is posted.
Contact. Exordium Data Management Cyber Security Services L.L.C, Al Hadi 3 St, Al MZEER’AH, Abu Dhabi, UAE. Email [email protected]. General inquiries: [email protected].