• Cloud
  • Pricing
  • Customers
Sign in Create your account
  • Cloud
  • Pricing
  • Customers
Sign in Create your account

Developers

  • Documentation
  • API reference
  • SDKs & CLI
  • Changelog

Learn

  • Blog
  • Glossary
  • Tutorials

Company

  • About us
  • Contact sales
  • Support
  • Security
  • Legal
Join the Discord Talk with other builders.
  • Cloud
  • Pricing
  • Customers
Sign in Create your account

Developers

  • Documentation
  • API reference
  • SDKs & CLI
  • Changelog

Learn

  • Blog
  • Glossary
  • Tutorials

Company

  • About us
  • Contact sales
  • Support
  • Security
  • Legal

Policies

  • Privacy Policy
  • Terms of Service

License & SLA

  • Open-Source License
  • Cloud Production SLA
  • Dedicated Pro Support SLA

Security

  • Report a vulnerability

How to report a vulnerability

Last updated: January 4, 2025

Overview

At Blnk Finance, the safety and security of our customers' data are paramount. We highly value contributions from our community to help identify and resolve vulnerabilities in our platform. If you discover a security issue with a CVSS score of 4.0 or higher, please report it to us.

How to report a vulnerability

Send an email to [email protected] with the following information:

  • Summary and Impact: A brief description of the vulnerability and its potential effects.
  • Steps to Reproduce: Clear, step-by-step instructions to replicate the issue.
  • Environment Details: Information about the environment you used (e.g., browser, operating system).
  • Proof-of-Concept: Any code snippets or methods that demonstrate the exploit, if available.

Scope of reporting

In scope:

  • Critical Areas:
    • Authentication bypass and privilege escalation.
    • Exposure of personally identifiable information (PII).
    • Unauthorized access to data outside the authenticated workspace.
    • SQL injection and remote command execution.
  • Affected Domains:
    • https://blnkfinance.com
    • https://cloud.blnkfinance.com
    • https://api.cloud.blnkfinance.com
  • Platforms: Help Scout, Discord, Slack, and GitHub integrations

Out of scope:

  • Automated scanning activities.
  • Social engineering attempts, including targeting Blnk employees.
  • Password brute force attacks.
  • Clickjacking on non-sensitive pages.
  • Missing security headers without demonstrable exploitability.
  • Issues reproducible only under highly unlikely conditions (e.g., outdated browsers, exotic operating systems).
  • Denial of Service (DoS) attacks.
  • Physical access attacks.
  • Theoretical vulnerabilities without proof of concept.
  • Logic bugs that allow bypassing account limitations for free or paid features.

Our commitment

  1. Acknowledgment: We will confirm receipt of your report within 48 hours.
  2. Investigation: Our security team will assess and prioritize the vulnerability.
  3. Resolution: We are dedicated to fixing reported issues promptly.
  4. Communication: You will receive updates on the status of your report and any actions taken.
  5. Confidentiality: All reports are handled with strict confidentiality to protect both you and our users.

Responsible reporting guidelines

  1. Test Responsibly: Only assess vulnerabilities on your own account or with explicit permission.
  2. Respect Privacy: Avoid actions that could lead to data breaches, data loss, or service interruptions.
  3. Limit Access Attempts: Do not attempt to gain unauthorised access beyond what is necessary to demonstrate the vulnerability.
  4. Maintain Confidentiality: Do not disclose the vulnerability publicly before reporting it to us, and allow us adequate time to address the issue.

Launch today

Launch with Blnk Cloud

Want a production-grade, scalable ledger and dedicated support? Sign up now and start building in minutes, or talk with us first.

Create your account Talk to us

See what you'll pay

Estimate your monthly cost with transparent, usage-based pricing.

Pricing calculator

Start building

Run this in your terminal to start Blnk locally.

bash
$git clone https://github.com/blnkfinance/blnk && cd blnk && docker compose up
Explore docs

Developers

  • Documentation
  • API reference
  • SDKs & CLI
  • Changelog
  • Status

Tools

  • Watch
  • MCP
  • Maps

Resources

  • Blog
  • Pricing
  • Customer stories
  • Glossary
  • Community

Support

  • Get Support
  • Pro support plans

Company

  • About us
  • Contact sales
  • Security & Compliance
  • Report vulnerability

Legal

  • Open-source
  • SLAs
  • Terms of Service
  • Privacy Policy

United States

© 2023 – 2026 Blnk Finance LLC

We only use cookies for analytics. Read our privacy policy to learn more.