Responsible disclosure

Legal

Responsible Disclosure

Effective Date: October 2026

At Blutui, we take the security of our systems and users seriously. We appreciate the efforts of ethical hackers and security researchers who help identify vulnerabilities in a responsible manner.

However, please note the following:

No Bug Bounty or Compensation Policy

Blutui does not operate a vulnerability rewards programme or offer financial compensation (bug bounties) for disclosed vulnerabilities. By submitting a report or otherwise notifying us of a security issue, you acknowledge and agree that:

  • You are acting voluntarily and without expectation of compensation.

  • Blutui is under no obligation to pay you for your time, effort, or any information you provide.

  • Submission of a vulnerability report does not create any form of contract, partnership, or entitlement between you and Blutui.

Responsible Disclosure Guidelines

We encourage users and researchers to contact us if they believe they have found a potential security issue. However, we ask that any disclosure be accompanied by a complete, clear, and reproducible report. A proper report should include:

  • A detailed description of the vulnerability.

  • Steps to reproduce the issue.

  • Any relevant URLs, parameters, or payloads.

  • Screenshots, logs, or video proof where appropriate.

  • An assessment of potential impact, if known.

Reports lacking sufficient detail may not be reviewed.

Please submit responsible disclosure reports to: security@blutui.com

Scope and Expectations

We request that you:

  • Avoid accessing or modifying data that does not belong to you.

  • Do not carry out denial-of-service, load or stress testing, or any test that could degrade the Services for other customers.

  • Comply with all local, national, and international laws.

  • Respect user privacy and our platform’s integrity.

  • Do not use social engineering, phishing or physical attacks against Blutui staff, customers or premises.

  • Test only against your own account or a test account, and stop once you have enough to demonstrate the issue. If you access someone else's data by accident, stop, do not keep or share it, and tell us in your report.

  • Give us reasonable time to fix the issue before sharing any details publicly.

Authorisation for Good-Faith Research

If you make a good-faith effort to follow this policy, we consider your research authorised. We will not treat it as a breach of our Terms and Conditions, Acceptable Use Policy or Fair Use Policy, including their restrictions on security and vulnerability testing, and we will not take legal action against you for it.

When you report an issue, we will acknowledge your report, keep you updated while we investigate, and let you know when it has been resolved.

Activity that goes beyond this policy, or that is malicious or illegal, is not covered by the authorisation above. We may take appropriate legal or administrative action in response, including under our Terms and Conditions and Acceptable Use Policy.

We thank you for your help in keeping Blutui secure.