TRUST CENTER
Responsible disclosure
How to report a suspected vulnerability safely.
Last reviewed: 31 August 2026
Contact
Report privately
Email hello@beetl.net with the subject ‘Security report’ and include the affected URL, impact, reproducible steps and a safe proof of concept. Do not include unnecessary personal data or customer content. A dedicated security mailbox remains a production-readiness action.
Safe testing
Boundaries
Use accounts and data you control. Do not perform denial of service, social engineering, destructive testing, persistence, bulk extraction, or access another customer's workspace.
Response target
Acknowledgement
The draft operational target is acknowledgement within two business days and a severity-based update cadence. This target requires an assigned incident owner before production launch.
No bounty promise
Recognition
Beetl does not currently promise a paid bug bounty. Coordinated public disclosure timing must be agreed with the incident owner.