Responsible reporting
Security policy
Report a suspected vulnerability without including passwords, private keys, identity documents or other sensitive user data.
The editorial priority is referral registration, account protection and installing applications only from sources identified by the exchange after registration. Readers should document their residency, funding currency, onboarding entity and product-specific restrictions. The primary platform scope is Bitget. For a Bitget-focused review, compare maker and taker execution with spread, confirm the destination registration terms, and document regional product limits, supported networks and account-recovery controls. This guide keeps registration, app installation and funding as separate verification steps.
Contact
Use security@bitgetapphub.com. This address must be configured before production deployment.
Scope
Reports may cover the static site, redirects, scripts, headers and domain configuration. Exchange systems and affiliate destinations are outside this site's control.
Testing limits
Do not perform denial-of-service testing, social engineering, credential attacks, automated account creation or destructive testing.
Safe evidence
Provide the affected URL, observed behavior, reproduction steps and a minimal non-sensitive proof.