Security
Our commitment to security maturity — and how to report a vulnerability responsibly.
Last updated: To be confirmed
Our approach
As a security organisation, we hold this website to the standards we advocate. It is served over HTTPS with HSTS, a strict Content-Security-Policy, and modern security headers. Contact submissions are validated and sanitised server-side, protected against automated abuse, and never exposed publicly.
Responsible disclosure
We welcome reports from the security community. If you believe you have found a vulnerability in this website, please contact us before disclosing it publicly, and give us a reasonable opportunity to investigate and remediate.
Report vulnerabilities to info@bergmans.ng. Please include enough detail to reproduce the issue. We ask that you avoid privacy violations, service degradation and data destruction while researching.
Scope
This policy covers this public website. It does not authorise testing of any other systems, and it does not grant permission to access data that is not your own.