Bridge Trading handles brokerage connections and live order routing. We take
security reports seriously and appreciate researchers who report issues to us
privately before disclosing them publicly.
How to report
- Email [email protected]
with a description of the issue, steps to reproduce, and the impact you believe it has.
- Machine-readable contact details are published at
/.well-known/security.txt.
- Please give us a reasonable window to investigate and fix before any public
disclosure. We ask for 90 days, and we will tell you sooner if a fix ships earlier.
What we commit to
- Acknowledge your report within 3 business days.
- Keep you informed of triage status and remediation progress.
- Not pursue legal action for good-faith research that follows the rules below.
- Credit you in our changelog (if you want credit) once the issue is fixed.
Rules for good-faith research
- Do not access, modify, or destroy data that is not yours. If a proof of concept
exposes another user's data, stop at the minimum needed to demonstrate the issue.
- Do not degrade the service (no denial-of-service, spam, or resource-exhaustion testing).
- Do not place, modify, or cancel brokerage orders on accounts you do not own.
- No social engineering of Bridge staff or customers, and no physical attacks.
- Only test against accounts you created yourself.
In scope
bridgetrading.ai and its subdomains — the web app, API endpoints, and authentication flows.
Out of scope
- Third-party services we integrate with (brokerages, SnapTrade, Stripe, data providers) —
report those to the vendor directly.
- Findings that require a victim's device or browser to already be compromised.
- Missing security headers or best-practice suggestions without a demonstrated exploit path
(still welcome, just triaged at lower priority).
- Volumetric denial of service.
We do not currently run a paid bug bounty. Rewards, when offered, are discretionary.
This page is a disclosure policy, not a contract.