Skip to content

Latest commit

 

History

History
32 lines (19 loc) · 1.19 KB

README.md

File metadata and controls

32 lines (19 loc) · 1.19 KB

Bug bounties

BES does not operate a bug bounty program.

Beg bounties

Beg bounties will not be accepted either.

By all means, if you find an actual security vulnerability then contact us and tell us what it is. If you find something awesome then we'd love to send you some stickers. But if you've just run some automated tooling, found something trivial then reached out with the expectation of cashing in, you're going to be disappointed.

Reporting

For Tamanu, use its github security vulnerability disclosure page.

For all other reports, or if you're not sure, email [email protected].

You may also wish to consult our security.txt file.

Scope

BES runs a number of test sites. These are out of scope for data breaches and credential compromise.

BES is frequently found when researching systems that we interact with but do not develop. You may be looking for:

Acknowledgments

  • (2025-02-10) Omri — A DNS configuration issue