Responsible Disclosure Policy

Prepared by Offensive Security  ยท  September 2026

Introduction

At Royal BAM Group, we take the security of our systems and data seriously. Despite our best efforts, vulnerabilities may still exist. We value the work of security researchers who help us keep our users and systems safe.

This responsible disclosure policy describes how you can report a security vulnerability to us, what we ask of you, and what you can expect from us in return.

Scope

In scope

  • bam.com and its publicly accessible subdomains (*.bam.com)
  • Public-facing web applications and APIs operated by BAM

We are particularly interested in vulnerabilities that put BAM data, users or systems at real risk. Examples include authentication bypass, injection, insecure direct object references (IDOR), server-side request forgery (SSRF), remote code execution (RCE) and exposure of sensitive data.

Out of scope

  • Denial-of-service (DoS/DDoS), brute-force attacks or volumetric load testing
  • Social engineering or phishing of employees, customers or suppliers
  • Physical access to BAM offices, sites or equipment
  • Internal networks and systems that are not directly reachable from the internet
  • Third-party services that BAM does not operate (please report these to the vendor concerned)
  • Automated scanner output without a demonstrated security impact
  • Low-impact findings such as missing security headers or cookie flags, SPF/DKIM/DMARC configuration, clickjacking on pages without sensitive actions, self-XSS, or software version disclosure
     

Not sure whether something is in scope? Ask us first at responsible.disclosure@bam.com.

What we promise

If you act in good faith and follow this policy, BAM commits to the following:

  • Safe harbour. We will not take legal action against you or file a police report for research carried out in accordance with this policy. If a third party takes legal action against you over such research, we will make it known that you acted in line with this policy.
  • A timely response. Every report receives a personal acknowledgement, a severity assessment and regular status updates until the issue is resolved.
  • Resolution. We will investigate every valid report, resolve it within a reasonable timeframe based on its severity, and let you know once it has been resolved.
  • Protecting your details. We treat your report and personal details as confidential. We will not share your details with third parties without your consent, unless we are legally required to do so.

     

Rules of engagement

We ask security researchers to test responsibly. 

Please do:

  • Test only assets that are in scope
  • Stop as soon as you have a minimal proof of concept
  • Use only your own test accounts and data
  • Report your findings promptly, with enough detail for us to reproduce them
  • Keep your findings confidential, and do not share or publish any details without our prior written consent
  • Stop and tell us in your report if you accidentally access personal or confidential data, and do not keep a copy

Please don't:

  • Access, copy, modify or delete data that does not belong to you
  • Degrade, disrupt or overload any service
  • Move further into our systems once a vulnerability is confirmed
  • Install backdoors, malware or other persistent changes on our systems
  • Use social engineering, physical access or spam
     

How to report

Email your report to responsible.disclosure@bam.com and include:

  1. Affected asset: the URL, endpoint or IP address, and confirmation that it is in scope
  2. Vulnerability type: a short description of the type of issue
  3. Steps to reproduce: clear step-by-step instructions or a minimal proof of concept
  4. Impact: what an attacker could realistically achieve
  5. Testing details: when you tested and the IP address(es) you tested from, so we can distinguish your activity from real attacks
  6. Contact details: how we can reach you

Recognition

BAM does not pay cash bounties. We do recognise good-faith contributions in other ways:

  • Personal thanks. A named point of contact who keeps you informed throughout the process.
  • A token of appreciation. For valid reports with higher impact, BAM may offer branded merchandise or a small gift voucher.
     

Tokens of appreciation are at BAM's discretion and depend on the severity, quality and originality of the report. They are only offered to researchers who have followed this policy, including its confidentiality requirements. They are not guaranteed, have no cash value and are not negotiable. Each unique, valid vulnerability is recognised once, and only for the first reporter.

Response times

We aim to meet the following targets:

MilestoneTarget
Acknowledgement of your reportWithin 3 working days
Triage and severity assessmentWithin 10 working days
Status updatesAt least every 30 days until resolved
ResolutionBased on severity; we will inform you once resolved

Legal

This policy does not authorise any testing outside the rules described above. Activities that do not comply with this policy or with applicable law may result in criminal or civil liability.

If you are unsure whether an action complies with this policy, stop and contact us at responsible.disclosure@bam.com before continuing.
 

Contact

Email: responsible.disclosure@bam.com
Security.txt: https://www.bam.com/.well-known/security.txt