Vulnerability Disclosure Policy
How to report a suspected vulnerability in the Banalytics website, Portal or software distributed by Banalytics.
Send a security report
E-mail info@banalytics.live with the subject Security report. Include the affected product, version or URL, a clear description, safe reproduction steps, potential impact and any non-sensitive proof of concept.
Do not send passwords, API keys, personal data, recordings, customer configurations or other sensitive payloads by ordinary e-mail. Banalytics will arrange a more appropriate channel if those materials are necessary.
Systems covered
- banalytics.live and the public Banalytics website;
- the hosted Banalytics Portal;
- Banalytics Agent and modules distributed by Banalytics;
- release and update mechanisms operated by Banalytics.
Customer networks, cameras, sensors, custom modules and third-party services are outside this policy unless the report demonstrates a vulnerability introduced by software distributed by Banalytics.
Testing rules
- Use only accounts, Agents and data that you own or are expressly authorised to test.
- Do not access another person’s data, bypass their permissions or persist after demonstrating the issue.
- Do not use denial-of-service, destructive, high-volume, social-engineering or physical attacks.
- Minimise data access and stop if personal or confidential information becomes visible.
- Allow Banalytics a reasonable opportunity to investigate and coordinate disclosure before publication.
What to expect
Banalytics is an early-stage company and does not currently operate a bug-bounty programme or promise a fixed response or remediation SLA for Community Edition. Good-faith reports are recorded, reviewed by the technical co-founder, prioritised by likely impact and tracked through remediation or an explained disposition.
Where a vulnerability triggers a legal reporting or customer-notification duty, Banalytics will follow the applicable process described in Security incident response and Product security and CRA readiness.
Last updated: 23 July 2026.