BlueDot IT

Security and Vulnerability Reporting

Last updated: August 14, 2026

This page describes how to report a security concern, what authorization means for testing, and how security-related information is handled before and during an engagement.

Report a vulnerability

Use the BlueDot contact page for non-sensitive triage of a suspected vulnerability in a BlueDot-controlled public service or to ask about a security review. Include the affected URL or component, a concise description, and safe reproduction details. For sensitive reports, use the ciphertext-only onion disclosure drop or encrypt the report with the published public key before sending it through an agreed secure channel. Do not include passwords, private keys, access tokens, customer records, regulated data, or other secrets in the public form.

Authorized disclosure and testing

Only test systems when you have explicit permission from the system owner and a written scope that identifies the authorized targets, methods, dates, access boundaries, and exclusions. Do not access, alter, copy, or retain data outside that scope. If testing reveals sensitive information or an unexpected impact, stop the activity, preserve only the minimum evidence needed, and report the issue through the agreed channel. Coordinated disclosure is expected before public release of details.

Inquiry data handling

Security inquiries are handled as project or operational information rather than as a place to deposit sensitive material. BlueDot collects the information needed to understand and respond to the request. The public contact form is not an encrypted vulnerability-submission portal; follow the instruction not to submit credentials, regulated data, customer records, or other sensitive content. See the Privacy Policy for website information handling.

Retention and deletion

Inquiry and vulnerability-report information is retained only as long as reasonably needed to triage, respond, maintain operational records, handle disputes, meet legal obligations, and protect systems. Project materials are handled according to the applicable written agreement. Deletion requests are considered where applicable, although security, legal, contractual, or accounting records may need to be retained.

Authorization records

Security testing and access to client systems require a documented authorization record. The written scope should identify the owner or approving authority, targets, permitted actions, credentials or access method, testing window, emergency contact, data-handling expectations, and stop conditions. A message sent through the public contact form does not by itself authorize testing.

Secure file exchange

Do not attach sensitive reports, source code, credentials, exports, or customer data to an initial public inquiry. After an engagement is scoped, BlueDot and the client can agree on a secure file-exchange method appropriate to the material, access needs, retention requirements, and client policy. The exchange method and handling expectations should be recorded with the engagement scope.

See the security.txt policy record, Privacy Policy, and Website Terms. For a scoped review or a non-sensitive initial report, contact BlueDot IT.