Security & legal

Security

How we approach security in the products we build and the infrastructure we run, and how to reach us if you find a problem.

Practices

What we build into the platform

These are properties of how the software is built and operated. They are not certifications, and we do not present them as such.

Least privilege by default

Access is granted per role and per environment rather than broadly, and is reviewed when a role changes.

Encrypted in transit

Traffic to our services runs over TLS. Certificates are managed automatically and renewed well ahead of expiry.

Change history on what matters

Configuration and record changes are captured in an append-only history, so a question about the past has an answer.

Data minimisation

We design to hold the minimum needed for the purpose at hand, because the safest data is the data never collected.

Hardened runtime

Production containers run unprivileged, with a read-only root filesystem and dropped capabilities.

Human review where it counts

Ambiguous automated findings are escalated to a person rather than resolved silently by a heuristic.

Last updated 27 August 2026

Reporting a vulnerability

If you believe you have found a security issue in a ByteSurge Labs product, website, or service, email dev@bytesurgelabs.com with Security report in the subject line.

Helpful reports usually include:

  • What you found, and which product, domain, or endpoint it affects
  • The steps needed to reproduce it
  • What an attacker could do with it, in your assessment
  • Any logs, requests, or screenshots that make it easier to confirm

What we ask

  • Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.
  • Do not access, modify, or delete data that is not yours, and do not run testing that degrades service for other people.
  • Use only your own accounts and test data when demonstrating an issue.

What you can expect from us

  • An acknowledgement that a human has read your report
  • An honest assessment of whether we agree it is a vulnerability
  • An update when it is fixed, and credit if you would like it

We do not currently run a paid bug bounty. We do take reports seriously and we will tell you plainly what we intend to do about them.

Security review and documentation

Architecture detail, deployment options, data-residency specifics, and completed security questionnaires are shared directly with prospective and existing customers rather than published here, so they always reflect the current system. Ask via Contact Sales and we will send the current set.