Bluesphere
  1. Platform
    • AI-AUGMENTED PENTESTING PLATFORM
      BlueSphere harnesses the precision of AI and the creativity of expert pentesters to secure your assets continuously and at scale.
      • PLATFORM OVERVIEW
      • Bluesphere
        Bluesphere Platform
        Access to on-demand researchers, vulnerability management, integration, and reporting
        Compliance
        Turn penetration testing results into compliance evidence. Automated mapping to PCI-DSS, ISO 27001, SOC 2, GDPR, HIPAA, and more.
      • Api Security
        new
        Discover API vulnerabilities before attackers do with automated OWASP Top 10 scanning, authentication testing, and actionable remediation insights.
      • BlueAI
        new
        Automated security analysis powered by AI. Scan code, detect verified secrets, and prioritize vulnerabilities across your entire codebase.
  2. Solutions
    • AI-AUGMENTED PENTESTING PLATFORM
      BlueSphere harnesses the precision of AI and the creativity of expert pentesters to secure your assets continuously and at scale.
      • SOLUTIONS OVERVIEW
      • Penetration Testing Overview
        Vulnerability Management
      • Api Security Solutions
  3. Pricing
Get Started

Vulnerability Disclosure Policy

Last updated: 21 juin 2025

This Policy applies exclusively to BlueSphere Security Ltd's independent security research. It does not govern confidential penetration testing engagements conducted under a Customer Agreement, which are separate and subject to distinct contractual obligations.

I. Purpose

BlueSphere Security Ltd ("BlueSphere") and its security team regularly conduct independent research into the security of widely used applications, systems, and services. This research is carried out to protect end users and improve the overall security posture of the digital ecosystem.

BlueSphere recognises that responsible disclosure must strike a balance between allowing vendors sufficient time to remediate vulnerabilities and ensuring that end users are not left exposed. This Vulnerability Disclosure Policy ("Policy") defines the process by which BlueSphere discloses security vulnerabilities to product and service vendors, and when applicable, to the general public.

II. Scope

This Policy applies to all security vulnerabilities discovered by BlueSphere during its independent research activities, including but not limited to:

  • Vulnerabilities in third-party software, applications, or services
  • Misconfigurations exposing sensitive data or systems
  • Security flaws in hardware or firmware
  • Exposed infrastructure or publicly accessible sensitive endpoints

This Policy does not apply to findings arising from contractual penetration testing engagements with BlueSphere customers. Those findings are handled exclusively under the relevant Customer Agreement and applicable confidentiality obligations.

III. Disclosure Process & Timelines

Upon identifying a security vulnerability, BlueSphere follows the structured disclosure process below:

  • Day 0 — Initial Notification BlueSphere identifies appropriate contact channels (security@ address, official disclosure programme, or formal contact mechanism) and transmits vulnerability details securely to the vendor.
  • Day 0–5 — Acknowledgement Window The vendor is expected to acknowledge receipt within 5 business days. If no response is received, BlueSphere initiates a second contact attempt through alternative channels.
  • Day 20 — No-Response Threshold If all contact attempts are exhausted without any vendor response, BlueSphere reserves the right to publish a public advisory 20 business days after the initial notification attempt.
  • Day 0–20 — Remediation Period Upon vendor acknowledgement, BlueSphere grants up to 20 calendar days for the vendor to develop and release a patch or effective mitigation.
  • Day 20 — Public Disclosure At the end of the remediation period, BlueSphere publishes a public advisory — whether or not a patch has been released — including technical details and recommended mitigations to assist the defensive security community.

IV. Extensions & Exceptional Circumstances

BlueSphere acknowledges that some vulnerabilities may require more than 20 days to remediate due to complexity, dependency chains, or compatibility constraints. Extensions may be granted on a case-by-case basis.

In the interest of transparency, if any extension is granted, BlueSphere will publish the full communication history with the vendor at the time of eventual public disclosure. This allows the security community to understand the remediation challenges vendors face when addressing high-impact vulnerabilities.

V. Immediate Public Disclosure

In circumstances where BlueSphere determines that a vulnerability poses an immediate and significant risk to the safety of end users — including active exploitation in the wild, critical infrastructure exposure, or mass data leakage — BlueSphere reserves the right to notify the vendor and the general public simultaneously.

In all cases of immediate disclosure, BlueSphere will provide the vendor with a written explanation of the factors that led to this decision.

Immediate disclosure is reserved for exceptional circumstances only. BlueSphere will always endeavour to act in the best interest of end users and to give vendors a fair opportunity to respond.

VI. Vendor Collaboration

BlueSphere is committed to working constructively with vendors throughout the disclosure process. This includes:

  • Providing clear technical documentation of the vulnerability and its potential impact
  • Assisting in understanding severity and exploitability
  • Offering to validate patches or proposed mitigations prior to public disclosure
  • Collaborating on coordinated public disclosure language where appropriate

If a vendor is unable or unwilling to patch a vulnerability, BlueSphere may offer to work with that vendor to publicly disclose the flaw alongside effective workarounds to protect end users.

VII. Contact

Service@bluesphere.dev

bluesphere.dev

BlueSphere Security Ltd — Registered in England and Wales

Experienced a breach?
Our experts are ready to respond swiftly, contain the threat, and restore your security.

Get immidiate assistance
Votre navigateur ne supporte pas la balise vidéo.
Votre navigateur ne supporte pas la balise vidéo.
Votre navigateur ne supporte pas la balise vidéo.
Votre navigateur ne supporte pas la balise vidéo.
Votre navigateur ne supporte pas la balise vidéo.
Votre navigateur ne supporte pas la balise vidéo.
Bluesphere

From Every Angle, Across Every Sphere  We Secure It All.

BlueSphere Security LTD
71-75 Shelton Street, Covent Garden,
London  WC2H 9JQ
Call - 02039542075
Service@BlueSphere.dev

Copyright © 2025 BlueSphere Security LTD. All Rights Reserved.

Platform
BluePlatform
BlueAI
Api Security
Compilance
Solutions
Vulnerability Management
Penetration Testing
Api Security Solutions
Attack Surface Management
Company
Privacy Policy
Terms of Service
Vulnerability disclosure policy
Pricing