Responsible Disclosure
How to report a suspected security vulnerability in this website or in a system we operate.
- Last updated
- 9 Sept 2026
Our commitment
We take security seriously and we welcome reports from security researchers and members of the public. If you report a genuine vulnerability in good faith and follow this policy, we will not pursue legal action against you.
We will acknowledge your report, investigate it, keep you informed of progress, and credit you if you wish once the issue is resolved.
How to report
Send your report to info@logintechbd.com with "Security" in the subject line. Please include enough detail for us to reproduce and assess the issue.
- The URL, endpoint or system affected.
- A clear description of the vulnerability and its potential impact.
- Steps to reproduce, including any request or payload used.
- Your name or handle, if you would like to be credited.
Please do
When testing, we ask that you:
- Give us reasonable time to investigate and remediate before any public disclosure.
- Use only your own accounts and test data.
- Stop as soon as you have confirmed a vulnerability exists, and avoid accessing more data than necessary to demonstrate it.
- Treat any data you encounter as confidential, and delete it once your report is submitted.
Out of scope
The following are not accepted under this policy:
- Denial of service, volumetric or load testing of any kind.
- Social engineering, phishing or physical attacks against staff or premises.
- Reports generated solely by automated scanners without a demonstrated impact.
- Issues in third-party services we do not control.
- Testing against systems we operate for clients, which requires the client's own written authorisation.
What to expect
We aim to acknowledge reports within five working days and to provide an initial assessment within ten working days. Remediation timelines depend on severity and complexity, and we will keep you updated until the issue is closed.
