We take the security of our platform and our customers’ data seriously. Transparency and security are core principles of our security program, and we are committed to continuously strengthening the measures we have in place to protect the confidentiality, integrity, and availability of our customers’ data.
For more information about our security practices, controls, and ongoing compliance initiatives, please visit our bsport Trust Center.
If you believe you have discovered a security vulnerability in our systems, we encourage you to report it to us privately so we can investigate and address the issue promptly.
Please send all security-related reports to security@bsport.io and include:
We ask that you avoid public disclosure of any potential vulnerability until we have had a reasonable opportunity to investigate and remediate it.
At this time, we do not offer monetary rewards or pay bug bounties for reported vulnerabilities. Submissions are accepted on a voluntary basis to help improve the security of our product.
Recognition
While we do not provide financial compensation, we are happy to publicly acknowledge and credit valid security reports. With your permission, we will recognize your contribution on HackerOne once the issue has been resolved.
bsport maintains a risk-based approach to information security. Our Security team works to identify, assess, prioritize, and mitigate risks that could affect our systems, services, or customer data.
Security risks are evaluated based on their potential impact and likelihood, with appropriate remediation measures implemented according to their severity. Our security practices and controls are reviewed and continuously improved as our products, infrastructure, and risk environment evolve.
As part of our ongoing security and compliance program, bsport is currently working toward SOC 2 compliance. Our SOC 2 program is in its early stages, and we are progressively formalizing, implementing, and testing the controls and processes required to support the framework.
bsport leverages a range of third-party applications and services to support the delivery of its products to customers. To manage the associated risks, bsport’s Security team has established a vendor management program that defines the security requirements and due diligence processes applicable to third-party and external vendor engagements.
As part of this program, bsport assesses the technical, physical, and administrative security controls implemented by its vendors to ensure they are appropriate and commensurate with the expectations of bsport and its customers. bsport also reviews the security controls and relevant assurance reports of its vendors on an annual basis to ensure that they continue to meet applicable security requirements. For a complete list of bsport's subprocessors, please visit our subprocessors list.
bsport continuously monitors its applications, infrastructure, networks, data storage environments, and system performance to help identify and respond to potential security and operational issues.
Security-relevant events are monitored and reviewed as part of our ongoing security operations, with appropriate action taken when potential risks or anomalous activity are identified.
We are committed to:
For additional information about bsport’s security practices and compliance initiatives, please visit our Trust Center.
We appreciate your help in keeping our platform secure and thank you for supporting responsible security research.