Legal

Vulnerability Disclosure Policy

Effective July 1, 2026  ·  Last updated September 13, 2026

The Successful Bookkeeper Global Inc., doing business as BKOS ("BKOS"), welcomes the responsible reporting of security vulnerabilities. This policy explains how to report a vulnerability and what you can expect from us in response.

1. Our Commitment

We are committed to working with the security community and our members to identify and resolve security issues quickly. We will:

  • Acknowledge your report within 3 business days;
  • Keep you informed of our progress;
  • Work to resolve confirmed vulnerabilities promptly;
  • Credit you (with your permission) for responsible disclosure.

2. What to Report

Please report any issue that could compromise the security or privacy of BKOS members, including:

  • Authentication or authorization bypasses;
  • Exposure of personal or sensitive member data;
  • Injection vulnerabilities (SQL, script, command);
  • Insecure direct object references;
  • Misconfigured security controls;
  • Any other issue you believe poses a security risk.

3. How to Report

Email: security@bkos.io

If your report is sensitive, you may request our PGP public key to encrypt your message.

Please include:

  • A clear description of the vulnerability;
  • The URL, feature, or component affected;
  • Step-by-step instructions to reproduce the issue;
  • Any screenshots, proof-of-concept code, or supporting evidence;
  • Your name or handle (optional — anonymous reports are accepted).

4. What We Ask of You

  • Do not access, modify, or delete member data beyond what is necessary to confirm the vulnerability;
  • Do not disrupt the Service or attempt denial-of-service attacks;
  • Do not exploit the vulnerability for any purpose other than confirming it exists;
  • Give us reasonable time to investigate and resolve the issue before disclosing publicly — we ask for a minimum of 90 days;
  • Do not discuss the vulnerability with others until we have resolved it and mutually agreed on a disclosure timeline.

5. Scope

This policy covers the BKOS platform at bkos.io and community.thesuccessfulbookkeeper.com.

Out of scope:

  • Third-party services and integrations (please report those to the respective vendor);
  • Social engineering or phishing attacks targeting BKOS staff;
  • Physical security;
  • Denial-of-service vulnerabilities that require significant infrastructure to reproduce.

6. Legal Safe Harbour

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith following this policy, avoid actions that harm BKOS, our members, or our infrastructure, and comply with the scope and responsible disclosure guidelines above.

We consider good-faith research under this policy to be authorized activity. If legal action is initiated by a third party against a researcher acting in good faith under this policy, we will take reasonable steps to make our authorization known.

7. Recognition

We appreciate responsible disclosure. With your permission, we are happy to acknowledge your contribution in our security acknowledgements. We do not currently offer a paid bug bounty program, but we may choose to offer a goodwill reward at our discretion for significant findings.

8. Contact

Security Team — The Successful Bookkeeper Global Inc. (operating as BKOS)

120 East Beaver Creek Road, Suite 200

Richmond Hill, Ontario L4B 4V1, Canada

security@bkos.io