Trust
Report a vulnerability
If you have found a weakness in Board Butler, we want to hear about it before anyone else does. This page says where to send it, what we will do with it, and what we will not do to you for sending it.
Safe harbour
If you research in good faith under the terms on this page, we will not bring or support legal action against you, and we will not ask your employer or your provider to act against you either. We will treat your work as authorised access for the purposes of any computer misuse law we could otherwise point at, and we will say so in writing if you ask.
Good faith means this: you stop as soon as you have shown the issue exists, you take no more data than the smallest amount needed to demonstrate it, you do not read, change, keep or share another person's records, you do not degrade the service for anyone else, and you give us a reasonable chance to fix the problem before you tell the world.
If you are unsure whether something is inside these terms, write to us and ask first. We would rather answer a question than read about a misunderstanding afterwards.
How to report
Send the report to security@boardbutler.com. One report per issue.
The report that helps most contains the affected address or screen, the account or role you were using, the steps in an order we can follow, what you expected and what actually happened, and any request or response that shows it. A short recording is welcome where the steps are hard to write down.
Tell us how you would like to be credited, or tell us you would rather not be. We follow whichever you choose.
What is in scope
The Board Butler application, the owner portal, the vendor and lender surfaces, the public API, the webhook endpoints, and this website.
The findings we care most about are the ones that cross a boundary the product promises to hold: reading or writing another corporation's data, moving money without the decision behind it, changing or removing a record that is supposed to be append only, bypassing a second factor on a financial role, or reaching a screen that a role should not reach.
What is out of scope
Denial of service, load testing and anything else that degrades the service for the boards using it. Social engineering of our customers, their owners or our people. Physical access attempts. Automated scanning that generates volume rather than findings.
Reports about a third party service we depend on belong with that third party. If you are not sure which of us owns the issue, send it here and we will route it.
A missing response header, a weak cipher on a service we do not run, an out of date version string, or a self reported scanner result with no demonstrated impact will be read and will usually be closed without a fix. Show us what an attacker gets and it becomes a finding.
What you can expect from us
We acknowledge every report within three business days, from a person rather than an autoresponder.
We give you a status within ten business days: what we reproduced, how we rated it, and what we intend to do. If a fix takes longer than that, we keep you updated rather than going quiet.
We tell you when the fix ships, and we credit you on this page if you asked to be credited. Where a report leads to an invariant test in our codebase, we will tell you that too, because that is the difference between fixing your finding and fixing its class.
There is no payment. Board Butler runs no bug bounty at launch, and we would rather say so here than let you spend a weekend on the assumption that we do.
Where our security programme actually stands
We run a SOC 2 readiness programme: the controls are implemented and the evidence is being collected. No audit has taken place, no report exists, and we will publish the auditor's report when there is one to publish.
No third party penetration test has been carried out. One is planned before launch and annually after that, scoped to the application, the portal, the public API and the webhook endpoints. Until it happens, the reports that reach this page are the outside review we have.
We publish no encryption key for this mailbox yet. If your report needs to travel encrypted, write to us first and we will arrange it rather than pointing you at a key that does not exist.
Questions researchers ask
Can I test against a real corporation's account?
No. Test against your own account or ask us for a sandbox. A sandbox session cannot write to real data, which is enforced by the database as well as by the application, so it is a safe place to work and a finding that defeats it is itself a report we want.
How long do I have to wait before publishing?
We ask for ninety days from your report, or until the fix ships if that comes sooner. If we go quiet on you, tell us you intend to publish and we will either respond or accept the consequence of not having.
Do you pay for reports?
Not at launch. We credit reporters who want credit, and we say plainly in the fix note what the report changed. If that changes we will say so on this page.
Send it to security@boardbutler.com
One report per issue, with the steps in an order we can follow. A person acknowledges every report within three business days.