Report a website security issue
If you believe you have found a security issue affecting brighttesting.eu, please report it privately to contact@brighttesting.eu with the subject “Security Disclosure – Bright Testing”. Please include enough detail to reproduce the issue without including unnecessary personal data or third-party secrets.
Safe research expectations
Please avoid destructive testing, denial-of-service activity, social engineering, accessing data that is not yours, persistence, or any action that could disrupt the website or other users. Stop testing if you encounter sensitive information and report the issue privately.
Client access principles
Where practical, Bright Testing prefers least-privilege accounts, staging or test environments, dedicated test data and access that can be revoked when the engagement ends. Production access is requested only when it is genuinely necessary and explicitly agreed.
Credentials and sensitive data
Do not submit passwords, API secrets, production credentials, payment-card data or unnecessary sensitive personal data through the public website. Secure exchange methods should be agreed separately when an engagement requires confidential material.
AI-assisted QA and client data
AI-assisted QA is treated as an explicit scope decision. Client credentials, proprietary source code, confidential product information or personal data should not be submitted to third-party AI systems unless that handling has been explicitly agreed for the engagement and is appropriate for the data involved.
Scope boundary
Bright Testing offers software QA services. Unless separately and explicitly agreed, these services are not a penetration test, vulnerability assessment or formal cybersecurity certification.
Response
Responsible reports will be reviewed as reasonably practicable. Bright Testing may ask for additional reproduction details and will avoid publishing reporter information without permission.
Updates
Last updated: 20 August 2026.