Security
Report a vulnerability.
We take the security of our members' data seriously. If you've found a vulnerability in a BCSA system, we want to hear from you — and we'll work with you to resolve it.
How to report
Email a description of the issue, the affected system or URL, and clear steps to reproduce it to security@bcsa.bn. Please include any proof of concept, but do not access, modify or delete data belonging to others.
Our machine-readable security contact is published at /.well-known/security.txt (RFC 9116).
Our commitment
- We will acknowledge your report within 5 working days.
- We will keep you informed as we investigate and remediate.
- We will not pursue legal action against researchers who report in good faith and follow the guidance on this page.
Scope & good-faith guidance
In scope are systems on the bcsa.bn domains. Please act in good faith:
- Give us a reasonable time to resolve the issue before any public disclosure.
- Avoid privacy violations, data destruction, and service disruption (no automated scanning that degrades availability, no denial-of-service).
- Only test against accounts you own or have explicit permission to use.
We do not currently run a paid bug-bounty programme, but we will publicly credit reporters who wish to be named.