Security
Security issues affecting btdigital.eu or a system directly operated by BT Digital may be reported to info@btdigital.eu.
1. What to include
- the affected domain, URL, system or component;
- a short and precise description of the issue;
- safe and minimal reproduction steps;
- the expected impact;
- evidence that does not contain unnecessary personal data, client data, credentials or bulk database extracts;
- your contact details.
2. Limits
This page does not grant general permission to perform security testing. Without prior written authorisation, do not: conduct denial-of-service or load testing; use social engineering; access or exfiltrate other users' data; establish persistence, backdoors or malware; modify, delete or publish data; test third-party systems; run high-volume automated scans.
If personal or client data becomes visible, stop testing immediately, do not copy or disclose it further, and report the issue without delay.
3. Response and rewards
BT Digital aims to acknowledge and investigate good-faith, sufficiently detailed reports. This page does not create a bug bounty programme, payment promise, service level commitment, or legal safe-harbour. These require a separate written agreement.
4. Client security testing
Security review or targeted testing of a client system is performed only under a separate, written and scoped authorisation from the client, with a defined time window and reporting process.
Effective date: 1 September 2026 | Version: 1.0