Skip to content

Security: bitwave-tv/bitwave

Security

SECURITY.md

Security Policy

Supported Versions

Currently, we only focus on security vulnerabilities for the most recent production version and newer. Older versions may be subject to 3rd party vulnerabilities or unreported issues that went undetected at the time.

Version Supported
1.24.x
< 1.23.0

Reporting a Vulnerability

Please immediately report any suspected vulnerabilities to support@bitwave.tv via email.

We respectfully request you respect the following guidelines:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Please allow us a reasonable amount of time (30 days) to evaluate and resolve the issue before you disclose it publicly.
  • If a vulnerability is resolved sooner than the requested allotment of time, we will update you letting you know, and may revise our requested disclosure date.

In compliance with these guidelines, we may offer a bug bounty for bugs and exploits that have high potential for abuse, or otherwise greatly compromises our service or user base.

Bug bounties are awarded as a courtesy, and makes no guarentee or promise of reward. We will communicate via email all relevant information, and welcome inquiry messages asking about our policies.

Please do not attempt to make demands from us in relation to a bug bounty, as this will result in an immediate disqualification.

There aren’t any published security advisories