Vulnerability disclosure

We run a research institute inside a security firm. If you find a vulnerability in this site or another Bridgham Technology Institute–owned property, we want to hear about it before anyone else does.

How to report

Email us the details

Send a report to headofresearch@bridghamcyber.com. Include what you found, the steps to reproduce it, and its potential impact. If your report is sensitive, say so and we'll arrange a secure channel to continue the conversation.

Scope

What's in scope

This site (bridghaminstitute.com) and other domains, apps, and infrastructure owned and operated by Bridgham Technology Institute. If you're not sure whether something is in scope, report it anyway and we'll tell you.

Our commitment

Good-faith research is welcome

We will not pursue legal action against researchers who report vulnerabilities in good faith, make a reasonable effort to avoid privacy violations and service disruption, and give us a reasonable window to address the issue before any public disclosure. We aim to acknowledge reports within five business days.

We do not currently run a paid bug bounty program. We're glad to credit researchers publicly, with permission, once an issue is resolved.