Vulnerability disclosure
Responsible disclosure for Bacenik CIQ™. Good-faith researchers are welcome.
Scope
- Signed-in application areas and public marketing pages
- Authentication, directory sync, connectors, and billing notification endpoints
- Out of scope: third-party identity or ERP consoles, social engineering, and denial of service
How to report
Email security@bacenik.com with reproduction steps, impact, and preferred contact. Do not exfiltrate customer financial evidence.
Safe harbor
We will not pursue legal action against researchers who act in good faith, avoid privacy violations, and give us a reasonable window before public disclosure.
How we protect data (summary)
- Sessions: signed session tokens
- Passwords: modern password hashing
- Secrets at rest: encrypted storage
- Two-factor: time-based authenticator codes
- In transit: TLS terminated by the hosting platform