Last updated: March 31, 2026
Blazemark takes the security of our platform and our customers' data seriously. We appreciate the work of security researchers who help us maintain a high security standard. This Vulnerability Disclosure Policy (VDP) explains how to report security vulnerabilities to us and what you can expect from us in return.
Blazemark operates a coordinated disclosure model: we ask that you do not publicly disclose a vulnerability before a fix has been shipped. We request a reasonable opportunity to investigate and remediate before any disclosure is made.
The following assets are in scope for this policy:
The following are explicitly out of scope and should not be tested:
We ask that you follow responsible disclosure practices:
We commit to not pursuing legal action against researchers who discover and report vulnerabilities in good faith, in accordance with this policy.
Blazemark will not initiate legal action against security researchers who:
We consider vulnerability research conducted consistent with this policy to constitute "authorized" access under applicable computer security laws. We will not bring a claim against you related to such research.
To report a vulnerability, please send an email to:
In the future, we may also accept reports via HackerOne. Check this page for updates on our HackerOne program once it is available.
Please include the following information in your report:
Please do not send vulnerability reports to our general support channel — use the security email address above.
We aim to respond to all valid vulnerability reports within the following timeframes:
| Milestone | Target |
|---|---|
| Acknowledgement of receipt | Within 48 hours |
| Initial triage and severity assessment | Within 7 days |
| Remediation (critical/high severity) | As soon as possible, typically within 30 days |
| Remediation (medium/low severity) | Within 90 days |
Blazemark does not currently operate a paid bug bounty programme. We are a coordinated disclosure programme only. We appreciate your contribution to improving our security and, where appropriate, we will credit researchers in our public acknowledgements.
For security-related enquiries, please contact: security@blazemark.org
For all other enquiries, visit blazemark.org or contact our support team.