Security Policy

Last updated: March 6, 2025

Thank you for your concern

Keeping customer data safe and secure is a huge responsibility and a top priority. We work hard to protect our users from the latest threats. Your input and feedback on our security is always appreciated.

Reporting security problems

Please report security vulnerabilities via our contact e-mail addresses below. We'll review your report and get back to you as soon as we can, usually within 72 hours.

Please e-mail our team if you have questions about the bug bounty program or don't hear back from us within 72 hours.

Security e-mail: security@bytesize.co

Tracking and disclosing security issues

We work with security researchers to keep up with the state-of-the-art in web security. Have you discovered a web security flaw that might impact our products? Please let us know. If you submit a report, here's what will happen:

We'll acknowledge your report.
We'll triage your report and determine whether it's eligible for a bounty.
We'll investigate the issue and determine how it impacts our products. We won't disclose issues until they've been fully investigated and patched, but we'll work with you to ensure we fully understand severity and impact.
Once the issue is resolved, we'll inform you of the result and pay any eligible bounty.
Bounties and Eligibility
Bounties range from USD $25 to $1,000 and scale according to impact and ingenuity, from an unlikely low-sensitivity XSS to a deep, novel RCE. One per bug; first discovery claims it; ties break toward the best written report.

The following areas are most important to us:

The following areas are considered out of scope and not eligible for a bug bounty:

Thanks for working with us! We respect the time and talent that drives new discoveries in web security technology.


This policy was adapted from the 37signals open-source policies / CC BY 4.0