Effective: 22 July 2026
If the Indonesian and English versions differ, the Indonesian version governs.
We value the security community’s help in keeping Bursa safe. If you find a security vulnerability, report it responsibly.
Responsible disclosure
What to report
- Security issues in the Bursa web application (bursanalar.com / bursanalar.vercel.app)
- Weaknesses in authentication, authorisation, or injection
- Data exposure that should not occur
- Misconfiguration that exposes sensitive data
What not to report here
- Spam/phishing (report to support@bursanalar.com)
- Non-security UI/UX bugs (report to support@bursanalar.com)
- Personal-data privacy complaints (use Data requests)
How to report
Email security@bursanalar.com with:
- Vulnerability description — in detail
- Reproduction steps — step-by-step so we can verify
- Potential impact — which data/functions are affected
- Proof of concept — screenshot or PoC (do not exploit real user data)
- Your contact — for follow-up
What we promise
| Commitment | Detail |
|---|---|
| Acknowledgement | Confirm receipt within 3 working days |
| Assessment | Severity evaluation within 7 working days |
| Fix timeline | Communicate a remediation timeline by severity |
| No retaliation | We will not pursue researchers who follow this policy |
| Recognition | Credit (if you want it) after the fix is verified |
Scope & limits
In scope
*.bursanalar.com,bursanalar.vercel.app- Public API endpoints
- Authentication & authorisation
Out of scope
- Social engineering / phishing
- DoS/DDoS attacks
- Physical security
- Third-party vulnerabilities (report to the vendor)
Prohibitions
- Do not access, modify, or delete other users’ data
- Do not exploit a vulnerability beyond verification
- Do not publish before we fix (coordinated disclosure)
- Do not use automated scanners that overload the system
Data incidents (leaks)
If you find evidence of an active data leak:
- Report immediately to security@bursanalar.com
- Do not download/archive user data
- We will activate the incident-response plan
Bug bounty
A bug-bounty program is not available yet. We will consider it after public launch and an external penetration test.
Contact
- Security: security@bursanalar.com
- PGP key: Available on request