Legal Document

Политика ответственного раскрытия

Policy for responsible reporting of security vulnerabilities affecting bi.expert systems and services.

Last revised: May 26, 2026. This policy applies to all interactions with bi.expert unless a stricter written agreement applies.

1. Purpose and reporting channel

bi.expert supports coordinated and responsible disclosure of security vulnerabilities. If you identify a potential vulnerability in our website, infrastructure or related services, please report it promptly to [email protected]. Include reproducible steps, affected endpoints, impact assessment and any relevant evidence so we can validate and triage quickly.

We request that reports are made in good faith, with respect for confidentiality and data protection obligations, and without public disclosure before remediation or coordinated publication timelines are agreed.

2. Rules of engagement and safe behavior expectations

Testing must avoid privacy harm, service disruption, unauthorized persistence and unnecessary data access. Do not exfiltrate personal data, alter business records, deploy malware, perform denial-of-service attacks or use social engineering against staff. If accidental access occurs, stop immediately and report details securely.

We aim to apply a good-faith safe harbor approach for researchers who follow this policy, act proportionately and avoid abusive behavior. This policy does not grant permission to violate law, bypass third-party rights or test systems outside our control.

  • Use the minimum level of interaction required to confirm an issue.
  • Do not retain, share or publish sensitive data discovered during testing.
  • Do not chain low-impact findings into high-risk exploitation in production systems.
  • Coordinate disclosure timelines with bi.expert before public publication.

3. Triage, response and communication

We target timely acknowledgement of valid reports and will provide status updates according to severity, exploitability and remediation complexity. Our triage process follows risk-based principles consistent with EU security governance expectations, including traceability, mitigation planning and post-incident learning.

Where a vulnerability has potential personal-data impact, we coordinate internal assessment with privacy governance and, where applicable, support incident notification obligations under GDPR and Dutch implementing law. Security and vulnerability communications can be sent to [email protected]. General legal notices can be sent to [email protected]. Address: Keurenplein 41, UNIT A6260, 1069 CD, Amsterdam, The Netherlands.