Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Security Policy & Responsible Disclosure

Legal · Security Policy · v.260624

Security Policy & Responsible Disclosure

B5 Secure’s security program and responsible-disclosure process, including scope, safe harbor, and how to report a vulnerability.

← Legal & agreements  ·  Download PDF →

This Security Policy describes B5 Secure’s approach to security and our responsible-disclosure process. Security is core to what we build — B5 Secure is a Never Trust security framework — and we welcome good-faith research that helps us keep it strong.

1.Our Security Program

We follow a secure development lifecycle for the B5 Secure software, including code review, dependency management, and testing, and we publish the status of our certifications and assurance programs on our Trust Center. Cryptographic key custody, where applicable to a deployment, is designed to use validated hardware security modules. Because the software runs inside our customers’ environments, customers retain control of their own infrastructure, configuration, and data.

2.Reporting a Vulnerability

If you believe you have found a security vulnerability in the B5 Secure software, the Site, or our services, please report it to security@b5secure.com. Include a description of the issue, the affected component or URL, steps to reproduce, and any proof-of-concept. Please give us a reasonable opportunity to investigate and remediate before any public disclosure.

3.Safe Harbor

We will not pursue or support legal action against researchers who, in good faith, comply with this Policy; access only their own data or test data; avoid privacy violations, data destruction, and service degradation; and do not exfiltrate data beyond the minimum needed to demonstrate the issue. If legal action is initiated by a third party against you for activity conducted under this Policy, we will make this authorization known.

4.Scope and Exclusions

In scope: the B5 Secure software, b5secure.com, and B5 Secure–operated developer services. Out of scope: third-party services we do not control, volumetric denial-of-service testing, social-engineering of our staff or customers, and physical attacks. Findings that require unrealistic user interaction or that have no security impact may be deemed informational.

5.Our Commitments

We will acknowledge your report, work to validate and triage it promptly, keep you informed of remediation progress, and credit you for the discovery if you wish. We coordinate disclosure timelines with reporters and aim to resolve valid issues on a reasonable, risk-based schedule.

6.Contact

Security reports: security@b5secure.com. General security questions may also be directed there. B5 SECURE LLC, PO Box 1410, Menlo Park, CA 94026-1410.

Download PDF These terms are accepted by your access to and use of the B5 Secure website and materials.

Scroll to Top