Security
Posture, disclosure path and security.txt.
Reporting a vulnerability
Email security@bvlogic.com with steps to reproduce. We aim to acknowledge within three business days. Please do not test in ways that degrade service for others or access data that isn't yours.
Current posture
- TLS on all traffic, HTTP redirects to HTTPS, certificates auto-renewed
- Tools execute client-side — files you analyse are not uploaded to us
- Analytics is cookieless by default; optional cookies load only on consent
- No third-party scripts load before consent
Certifications
We hold no formal certification today. We will state it here when that changes rather than imply it beforehand.