Skip to main content

Security

Who is responsible for security at Bleam and how to report a vulnerability to us.

Last updated: October 7, 2026

Security lead

Lead

Marius LE COZ
Managing Director of Cyad SAS, responsible for the security of Bleam products

Security contact

marius@bleam.app

Scope

This policy covers the services operated by Cyad SAS:

  • the bleam.app website and its subdomains;
  • the Bleam Chrome extension;
  • the Bleam APIs and backend services.

Reporting a vulnerability

If you believe you have found a security issue, email us at marius@bleam.app. Please include the affected service, steps to reproduce and the potential impact.

We aim to acknowledge reports within 5 business days and to keep you updated on the fix.

Rules of engagement

  • Only access the data strictly needed to demonstrate the issue, and never other users' data.
  • No denial of service, spam or social engineering.
  • Only test with accounts you own.
  • Give us reasonable time to fix the issue before any public disclosure.

Out of scope

Vinted and the third-party services we rely on (hosting, payments, authentication) are not covered by this policy: please report issues affecting them directly to those providers.

Rewards

We do not run a paid bug bounty program at the moment, but with your consent we publicly thank people who report issues in good faith.