Access & Security
Vulnerability Disclosure & Security Reporting Policy
How to report a security concern, how reports are evaluated, and our commitment to working responsibly with those who help improve platform security.
- Document ID
- SEC-005
- Version
- 1.0.0
- Status
- Active
- Classification
- Public
- Owner
- Big Bull Technologies, LLC
- Effective
- 20 July 2026
- Next review
- July 2027
01 Purpose
Big Bull Technologies, LLC (“Big Bull Technologies,” “BBT,” “we,” “our,” or “us”) is committed to maintaining the security of Before the Call (“B4C”) and appreciates the responsible disclosure of potential security vulnerabilities.
This policy explains how security concerns may be reported, how reports are evaluated, and our commitment to working responsibly with individuals who help improve platform security.
02 Our Philosophy
Security is an ongoing process.
No software platform is immune from vulnerabilities, and responsible disclosure plays an important role in maintaining a secure environment.
We welcome reports submitted in good faith and appreciate responsible collaboration from the security community, Customers, and Authorized Users.
03 What Should Be Reported
Examples of issues that should be reported include:
- Authentication bypasses
- Authorization issues
- Privilege escalation
- Data exposure
- Injection vulnerabilities
- Cross-site scripting (XSS)
- Cross-site request forgery (CSRF)
- Remote code execution
- Broken access controls
- Sensitive information disclosure
- API security concerns
- Mobile application security issues
- Infrastructure vulnerabilities
- Other security weaknesses that could reasonably affect the confidentiality, integrity, or availability of the platform
If you are unsure whether an issue qualifies, we encourage you to report it.
04 How to Report a Vulnerability
Security concerns should be reported through the official security contact information published by Big Bull Technologies.
Reports are most helpful when they include:
- A clear description of the issue
- Steps to reproduce the behavior
- The affected feature or service
- Screenshots or supporting evidence, when appropriate
- Your contact information for follow-up questions
Providing sufficient detail helps us investigate efficiently.
05 Good Faith Research
Big Bull Technologies supports responsible, good-faith security research. We ask researchers to:
- Avoid disrupting production systems
- Avoid accessing data that does not belong to them
- Avoid modifying or deleting Customer information
- Avoid social engineering, phishing, or physical attacks
- Avoid denial-of-service testing
- Avoid automated activity that could negatively impact platform availability
Testing should be limited to actions reasonably necessary to demonstrate the reported issue.
06 Coordinated Disclosure
We request that reported vulnerabilities not be publicly disclosed until Big Bull Technologies has had a reasonable opportunity to investigate and address the issue.
Coordinated disclosure helps protect Customers while remediation efforts are underway.
07 Our Commitment
When a vulnerability is reported in good faith, Big Bull Technologies will make reasonable efforts to:
- Acknowledge receipt of the report
- Review the submitted information
- Assess potential impact
- Investigate the issue
- Implement appropriate remediation where necessary
- Communicate with the reporter when appropriate
Not every reported issue will result in a software change, but every report will be evaluated.
08 Safe Harbor
Big Bull Technologies will not pursue legal action against individuals who conduct security research in good faith and in accordance with this policy, provided their activities:
- Are intended to improve platform security
- Avoid unnecessary harm
- Respect Customer privacy
- Comply with applicable laws
- Remain within the scope of responsible disclosure
This Safe Harbor does not authorize activities that violate law, disrupt Services, access Customer data without authorization, or otherwise exceed the boundaries of responsible security research.
09 Bug Bounty Program
At this time, Before the Call does not operate a public bug bounty or financial reward program unless expressly announced by Big Bull Technologies.
We sincerely appreciate responsible security reports regardless of whether a reward program is in place.
10 Customer Security Responsibilities
Customers also play an important role in platform security. Departments are encouraged to:
- Report suspected security incidents promptly
- Remove access for former members
- Protect account credentials
- Enable Multi-Factor Authentication where available
- Keep supported applications updated
- Follow organizational security policies
11 Continuous Improvement
Big Bull Technologies continually reviews reported vulnerabilities to improve:
- Platform security
- Secure development practices
- Internal testing
- Monitoring
- Operational procedures
- Customer guidance
Lessons learned from reported issues help strengthen the platform over time.
12 Changes to This Policy
Big Bull Technologies may update this Vulnerability Disclosure & Security Reporting Policy periodically.
Material changes will become effective on the published Effective Date after reasonable notice has been provided through the Services, our website, email, or another appropriate communication method.
13 Contact
Security concerns should be submitted using the official security contact information published by Big Bull Technologies.
For general support requests, please use the standard customer support channels.
Big Bull Technologies, LLC
Email: ashlea@bigbulltech.io
14 Related Documents
15 Revision History
| Version | Date | Description |
|---|---|---|
| 1.0.0 | July 2026 | Initial publication. |