Scope
This policy covers assets controlled by BIK AI Technologies, S.L.U. under the biklabs.ai and biklabs.es domains, including the application and APIs where publicly available.
Third-party services, social engineering, physical attacks, denial of service, and testing against other people's accounts or data are out of scope.
Good-faith research
Use only your own accounts and data or assets for which you have express authorisation. Limit testing to what is necessary to demonstrate the issue and stop if you accidentally access another person's data, secrets, sessions, or functions that could cause harm.
Do not maintain persistence, modify or delete data, download more information than necessary, or attempt lateral movement across tenants, roles, or systems.
What a report should include
Identify the affected asset, vulnerability type, reasonable impact, prerequisites, and reproducible steps. Include relevant requests and responses, screenshots, or a minimal proof of concept, removing credentials and personal data.
- Affected URL, endpoint, version, or component.
- Environment and role used during testing.
- Observed impact and the scope you confirmed, without presenting extrapolation as fact.
- Temporary mitigation or suggested fix, if known.
- A secure channel through which we can reply.
After submission
We will acknowledge receipt where possible, prioritise the report by risk, and may request additional information. Investigation, remediation, and deployment depend on complexity and do not form an SLA unless expressly agreed.
Coordinate any publication with us. We will ask you not to disclose exploitable details until a reasonable fix is available or another date is agreed.
Research protection
If you act in good faith, follow this policy, and comply with applicable law, we will treat your research as authorised under our terms and will not take action merely because you performed that testing. This statement cannot authorise conduct against third parties or limit legal obligations outside our control.
Usually ineligible findings
Missing informational headers without impact, clickjacking on pages without sensitive actions, already-public enumeration, generic TLS recommendations, versions without demonstrated exploitation, and scanner-only reports without validation are not normally treated as vulnerabilities on their own.
Recognition and rewards
This policy does not create a bounty programme or guarantee payment, public recognition, or employment. Any recognition must be agreed in writing and must never be conditioned on a threat of disclosure.