Vulnerability Disclosure Program (VDP)
We take security seriously. If you discover a vulnerability, we want to hear from you.
Scope
In scope:
- *.bangladeshexport.com (all subdomains)
- bangladeshexport.com (main website + admin panel + API)
- Supplier portal and buyer portal
- Public invoice view and payment pages
Out of scope:
- Social engineering attacks
- DDoS attacks
- Physical attacks on data centers
- Vulnerabilities in third-party services not hosted by us
Rewards
| Severity | Bounty |
|---|---|
| Critical (RCE, SQLi, auth bypass) | $500 - $2,000 |
| High (privilege escalation, data leak) | $200 - $500 |
| Medium (XSS, CSRF) | $50 - $200 |
| Low (info disclosure, misconfig) | $25 - $50 |
How to Report
Send reports to: [email protected]
Please include:
- Description of the vulnerability
- Steps to reproduce (PoC)
- Impact assessment
- Suggested fix (optional)
Acknowledgments
We thank the following researchers who have helped improve our security:
(No reports yet — be the first!)
Safe Harbor
We will not pursue legal action against researchers who:
- Make a good faith effort to avoid privacy violations, data destruction, and disrupting service
- Only interact with accounts they own or have explicit permission to test
- Provide us with reasonable time to remediate before public disclosure