Security
Report a security concern responsibly.
Biteyield welcomes good-faith reports that help protect investors, their account data and the platform.
What to include
Email [email protected] with the affected URL, a clear description, reproduction steps, expected impact and any non-sensitive evidence. Do not send passwords, access tokens, broker files or personal portfolio data by email.
Good-faith research
Use only accounts and data you own or have explicit permission to test. Avoid denial of service, automated high-volume scanning, social engineering, physical attacks and testing third-party providers. Give Biteyield a reasonable opportunity to investigate before public disclosure.
Response process
We aim to acknowledge a complete report within five working days, assess severity, keep the reporter informed when practical and address confirmed issues according to risk. This is a best-effort process for an independent personal project and is not a paid bug-bounty programme.
Machine-readable policy
The canonical security contact is published at https://biteyield.com/.well-known/security.txt.