Bugbop holds unpatched vulnerability reports about our customers' systems. That makes us a target, and we treat it that way. This page describes how we protect the platform and the data on it. It's written to be specific; if you need more detail for a security review, email [email protected] and we'll answer your questionnaire.
1. Where Your Data Lives
- All platform data is hosted on Amazon Web Services in the us-east-1 (N. Virginia) region. Backups stay in the same region.
- The database is encrypted at rest (AES-256) and replicated across availability zones. Automated backups are kept for 7 days with point-in-time recovery to any second in that window. We restore-tested it in October 2026: about five minutes to a usable copy.
- Uploaded attachments are stored with server-side encryption and versioning. Images are served through Cloudflare from unguessable keys; other files through short-lived signed links.
- All traffic is encrypted in transit. Cloudflare terminates TLS (1.2 minimum) and the connection from Cloudflare to our servers is encrypted too. HSTS is on.
- The application server only accepts web traffic from Cloudflare's network. The database isn't reachable from the internet at all.
2. Accounts and Access
- Passwords are hashed, never stored in plain text, 12 characters minimum.
- Two-factor authentication with an authenticator app is available to every account. 2FA secrets are encrypted at the application level.
- Accounts lock after repeated failed logins, and signup is protected against bots.
- Access inside Bugbop is per program. Bug Hunters only ever see their own reports. Program staff only see their own program, with owner, admin, triager and viewer roles that the program owner controls. Every authorisation decision is enforced on every request.
- Role changes and report changes are recorded in an audit history.
- Our own access to production is limited to key-based SSH from a single address and an AWS account protected by MFA.
3. How We Build and Ship
- Every change is reviewed and run through automated tests, static security analysis and dependency vulnerability checks before it ships.
- Every deploy is a fresh build that picks up the latest security patches. Rolling back to the previous release takes minutes.
- Dependencies are checked daily for known vulnerabilities, and security advisories reach us in real time.
4. Monitoring and Vulnerability Management
- Our cloud environment is monitored for threats, and the production host and every release are scanned for known vulnerabilities. Findings alert us in real time.
- Application errors are tracked and uptime is monitored externally around the clock.
- We run a public bug bounty program on Bugbop itself, on Bugbop. Security researchers test the platform continuously and get paid for what they find. Findings are fixed in severity order, critical first.
5. AI and Third Parties
- AI triage sends a report's title, description and the program's scope text to OpenAI. No Bug Hunter identity is attached. We have Zero Data Retention enabled, so OpenAI doesn't store the content and doesn't train on it.
- Identity verification is handled by Stripe Identity. Identity documents never touch our servers.
- Every service that processes your data, and what it sees, is listed in the Privacy Policy.
6. Incident Response
We have a written incident response plan. If we confirm a breach affecting your data, we'll tell you by email without undue delay and within 72 hours, with what happened, what data was involved, what we've done and what you should do. We notify the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme where it applies, and EU authorities where GDPR applies.
7. Policies and Compliance
Our security policies are written down and reviewed every year: information security, change management, business continuity and disaster recovery, incident response, cryptography and key management, access management, logging and monitoring, endpoint security and data classification, plus a maintained risk register. We operate under the Australian Privacy Act and GDPR for our EU users, and we stay out of PCI DSS scope by never handling card numbers ourselves.
We don't hold a SOC 2 or ISO 27001 certification. Our infrastructure providers do: AWS and Cloudflare publish their audit reports. If your procurement process needs a questionnaire completed, send it over and you'll get honest answers.