AWARDS The Bynder Spotlight Awards 2024: Winners revealed!

View the winners
v. 4.0

Responsible Disclosure Policy

Download as PDF

At Bynder, we are committed to keeping our systems, network and product(s) secure. Despite the measures we take, the presence of vulnerabilities will always be possible. When such vulnerabilities are found, we’d like to learn of them as soon as possible, allowing us to take swift action to shore up our security.

Under Bynder’s Responsible Disclosure Policy, you are allowed to search for vulnerabilities, so long as you don’t​:

Breaching the above restrictions may result in Bynder launching an investigation and/ or taking legal action to the greatest extent of Bynder’s legal obligation and rights or that of our partners and customers.

If you do discover a vulnerability, please contact us as soon as possible by sending an (encrypted) email to ​security@bynder.com​. To prevent information falling into the wrong hands, please use the following public key:

{globalset:securityKey:unformattedHtml}

What we ask of you:

What we promise:

Rewards and attribution:

Assets in scope:

Accounts that can be self provisioned at https://www.bynder.com/en/trial/

Out of scope assets:

Acquisitions:

Out of scope vulnerabilities:

The following template can be used when submitting a vulnerability:

# Description
[Description of the identified vulnerability]

# Steps to reproduce
1. Step 1
2. Step 2
[...]

# Impact
[What could an attacker achieve by exploiting the vulnerability​]

Any report submitted in relation to this Responsible Disclosure Policy will be handled with great care with regards to the privacy of the reporter. We will not share your personal information with third parties without your permission, unless we are legally required to do so.