Legal

Responsible disclosure

Operated by BHDicaire.com

This brand site shares the same owner, security contact, and responsible disclosure process as BHDicaire.com. Contact routes and some policies may point back to the main site.

If you believe you found a vulnerability affecting this website or its public infrastructure, thank you for taking the time to report it responsibly.

This page describes the human-readable policy behind the site’s security.txt file.

Scope#

In scope:

  • bhdicaire.com;
  • www.bhdicaire.com, if present;
  • published machine-readable files such as security.txt, robots.txt, humans.txt, and llms.txt; and
  • site configuration issues that could affect confidentiality, integrity, or availability.

Out of scope:

  • third-party services not controlled by me;
  • social engineering;
  • physical attacks;
  • denial-of-service testing;
  • spam, phishing, or credential-stuffing campaigns; and
  • findings that only affect outdated browsers or unsupported client software.

Rules of engagement#

Please:

  • report the issue promptly;
  • include enough detail to reproduce or understand it;
  • avoid accessing, changing, deleting, or exfiltrating data;
  • avoid persistence, lateral movement, and destructive testing;
  • do not publicly disclose the issue until I have had a reasonable chance to respond; and
  • stop testing if you encounter sensitive information or service instability.

How to report#

Use the contact route listed in /.well-known/security.txt . If encrypted communication is useful, use the encryption link listed there.

Include:

  • affected URL or component;
  • vulnerability type;
  • steps to reproduce;
  • impact;
  • screenshots or proof-of-concept details, if safe to share; and
  • your preferred contact method.

What to expect#

I will try to acknowledge good-faith reports within a reasonable time and may ask clarifying questions. This is a personal website, not a staffed bug bounty program, so response times may vary.

There is no monetary bounty for reports unless explicitly agreed in writing before testing.

Safe harbour#

I will not pursue legal action against good-faith security research that follows this policy, avoids harm, and does not violate privacy or disrupt the service. This does not authorize testing against third-party systems or services outside my control.