Home/Legal/Security Reporting

Security / Vulnerability Reporting

One address for security issues, vulnerabilities and suspected misuse of the BHS name.

Last updated: 17 September 2026

How to report

Email hriday.agm23@iimshillong.ac.in with the subject “Security report”. Reports are read by the people responsible for the issue raised.

What to include

  • A clear description of the issue and the impact you believe it has.
  • Where it is — the URL, page or component affected.
  • Steps to reproduce it, if it is a technical finding.
  • When you observed it.
  • How we can reach you for follow-up questions.

Please keep reports concise and do not attach third-party data, personal information or classified material. Email is not a secure channel: if a matter requires a protected channel, say so and we will agree one with you.

What this address is for

  • Security vulnerabilities affecting this website.
  • Suspected misuse of the BHS name, crest or identity, including messages that claim to come from BHS but do not.
  • Security concerns about correspondence you have received that appears to relate to BHS.
  • Suspected exposure of BHS information.

Before testing anything, please read our Responsible Disclosure policy, which sets out what is in and out of scope. Denial-of-service testing, social engineering, physical testing and any access to other people's data are out of scope.

What happens next

We acknowledge reports we receive, assess them, and act on what we find. We may come back to you with questions. We do not operate a bug-bounty programme and do not offer payment for reports.

Emergencies

This address is monitored during working hours and is not an emergency service. If people are at risk, contact your local emergency services or the relevant competent authority first.

General enquiries

For anything that is not a security matter, use the contact page.