Primary intake
Reports go through the security form first, with security@blast-audit.com as backup contact.
We use privacy-first analytics. Essential audience metrics run by default, marketing attribution only with explicit consent. Privacy Policy
Legal
How to responsibly report security vulnerabilities to Blast Audit.
Last updated: February 15, 2026
Primary intake
Reports go through the security form first, with security@blast-audit.com as backup contact.
Scope
In scope: blast-audit.com, relevant subdomains, and other public web assets operated by Blast Audit.
Response targets
Acknowledgement within 72 hours. Initial triage within 7 days. No monetary bounty at this time.
Blast Audit (NEXT BP) welcomes responsible disclosure of security vulnerabilities.
Preferred: Submit a report using this form:
Backup contact:
Please include:
In scope:
Out of scope:
We support good-faith security research.
If you avoid data access beyond what is necessary, do not disrupt services, test only in-scope assets, and report promptly, we will not pursue legal action against you for your research.
This is a vulnerability disclosure program. We do not currently offer monetary rewards.
Last updated: 2026-02-15