Security & Vulnerability Disclosure

How to report a security issue to BankScan AI.

Reporting a vulnerability

If you've found a security issue in BankScan AI — a vulnerability in our web application, an exposed credential, a way to access another user's data, anything that could put our users at risk — please tell us. We treat reports seriously and we don't pursue legal action against good-faith researchers.

Primary contact: security@bankscanai.com

Fallback (also monitored): mitchellagoma@gmail.com

RFC 9116 machine-readable record at /.well-known/security.txt.

What to include in your report

What we'll do

  1. Acknowledge within 2 working days. We'll confirm we've received your report and assign it a tracking reference.
  2. Triage and validate within 5 working days. We'll let you know whether we can reproduce the issue and what severity we've assessed.
  3. Fix according to severity. Critical issues (data exposure, RCE, authentication bypass): patched within 7 days. High: 30 days. Medium: 90 days.
  4. Coordinated disclosure. We'll work with you on a disclosure timeline. By default we ask for 90 days from report to public disclosure, sooner if a fix ships earlier.
  5. Acknowledge you in our security log (with your permission) once the fix is live.

Scope

In scope for this policy:

Out of scope:

Safe harbour

If you make a good-faith effort to comply with this policy, we will:

Please don't access user data beyond the minimum needed to demonstrate the issue, don't degrade the service for other users, and don't publish the vulnerability until we've had a chance to fix it.

What we cover internally

Our security posture is documented for HMRC's MTD recognition review at github.com/mitchell1972/bankparse under hmrc/docs/security-questionnaire.md, hmrc/docs/data-handling.md, hmrc/docs/audit-log.md, and hmrc/docs/incident-response.md (the 72-hour HMRC + ICO notification runbook). Key controls:

Effective: 26 May 2026
Last updated: 26 May 2026
Canonical URL: https://bankscanai.com/security