generated: '2026-08-06' method: searched probe: true source: https://www.bswift.com/bswift-vulnerability-disclosure-program/ name: bswift's Vulnerability Disclosure Program policy: - https://www.bswift.com/bswift-vulnerability-disclosure-program/ contact: [] intake: web form on the policy page bug_bounty: false bounty_platform: null security_txt: false scope: Any digital asset owned, operated, or maintained by bswift, including public-facing websites. accepts_reports_from: - independent security researchers - industry partners - vendors - customers - consultants commitments: - Acknowledge receipt of each vulnerability report - Investigate and validate reported issues - Work with the researcher through remediation researcher_expectations: - Communicate responsibly and allow time to validate and remediate - Avoid privacy violations, degradation of user experience, disruption of production systems, and destruction of data - Provide technical details sufficient to reproduce, via the published web form - Refrain from public disclosure of unverified vulnerabilities until bswift has responded evidence: - source: https://www.bswift.com/bswift-vulnerability-disclosure-program/ kind: disclosure-policy-page http_status: 200 fetched: '2026-08-06' - source: https://www.bswift.com/about/security/ kind: security-program-page http_status: 200 fetched: '2026-08-06' gaps: - No /.well-known/security.txt is served — https://www.bswift.com/.well-known/security.txt returns the WordPress home page (soft 404), and https://api.bswift.com/.well-known/security.txt returns HTTP 400 MISSING_AUTHENTICATION_TOKEN. - No published security@ contact address; intake is a web form only. - No named safe-harbor / legal-authorization clause and no disclosure SLA on the policy page.