Launch offer: 20% off for our founding clients, until 31 December 2026. See the offer

Security and responsible disclosure

Updated September 26, 2026

MyBebine is a product of Los Bebes Inc, a software and cybersecurity engineering company. We build this site the way we build for clients: collect as little as possible, validate everything on the server and give each component only the access it needs. No system is perfectly secure, so if you find a weakness, please tell us. This page explains how.

How is this website protected?

  • HTTPS only, with HSTS. Your browser connects to us over an encrypted connection and remembers to refuse insecure ones.
  • A strict Content Security Policy. Pages can run only the scripts and styles we have explicitly approved, which blocks most injected code.
  • No third-party scripts on public pages. There are no ad, analytics or tracking scripts, and our contact form’s spam check (a proof-of-work puzzle solved in your browser) runs on our own servers.
  • Minimal data collection. We ask only for what we need to reply to you (see our privacy policy).
  • Server-side validation. Every form submission is checked on our server for type, length and format. Checks in your browser are there for convenience, not security.
  • Rate limiting. Repeated submissions are throttled using a salted hash of the IP address, deleted within 24 hours.
  • Secrets stay on the server. API keys and credentials live in a secret manager, never in the code your browser downloads.
  • Deny-by-default database rules. Our database refuses all direct access from browsers; only our server code can read or write it. It is hosted in the EU (Belgium) and encrypted at rest by Google.
  • Least-privilege deployment. Our build, publishing and server components each have only the permissions they need.
  • Dependency audits. We keep third-party packages few and check them for known vulnerabilities whenever we update them.

How do I report a vulnerability?

Email support@mybebine.com with “Security” in the subject line. Please include:

  • The affected URL or component
  • What the issue is and what an attacker could do with it
  • Clear steps to reproduce, with any proof-of-concept code or screenshots
  • How we can reach you for follow-up

Please don’t include other people’s personal data in your report.

What happens after I report?

  • We acknowledge your report within 3 business days.
  • We investigate, keep you informed of our progress and tell you when the issue is fixed.
  • Please give us reasonable time to fix the issue before sharing details publicly. We’re happy to agree on a disclosure date with you.

What is in scope?

The mybebine.com website, including its pages, its forms and the server endpoints behind them.

What is out of scope?

  • Denial-of-service attacks, load testing or anything that degrades the site for others
  • Social engineering or phishing aimed at our team, clients or partners
  • Physical attacks against our offices or equipment
  • Spam, including bulk or automated form submissions beyond what is needed to show an issue
  • Third-party services we use, such as Google Firebase, WhatsApp and our email provider; please report to them under their own programs
  • Client websites and accounts we build or manage, which belong to our clients
  • Automated scanner reports without a demonstrated, exploitable impact
  • Best-practice suggestions with no demonstrated security impact, such as email SPF or DMARC settings
  • Values that are public by design, such as our IndexNow key and the spam-check puzzles

Not if you act in good faith and follow this policy. We consider such research authorized and will not pursue legal action against you for it. In return, please:

  • Test only with your own data and accounts, and never access, change or delete data that isn’t yours. If you come across someone else’s data, stop, don’t keep it and tell us.
  • Take only the minimum data needed to prove the issue.
  • Avoid denial of service, social engineering and spam.
  • Give us reasonable time to fix the issue before any public disclosure.

This commitment covers systems operated by MyBebine. We can’t authorize testing of third-party services.

Do you pay bug bounties?

Not at the moment. We don’t currently run a paid bug bounty program.

Where can I find more?

WhatsAppGet a quote
WhatsApp

This page, measured on your device

Largest paint
…
Interaction delay
tap anything
Layout shift
…
Server response
…
Page weight
…
Requests
…
Third-party
…
Trackers
0

Real numbers from your browser (lab conditions vary). CLS is only reported by Chromium browsers.

What AI crawlers read on this page

No JavaScript, no design: just the text and structured data that ChatGPT, Gemini, Perplexity and Google receive. We build every page to read well in both views.

Loading…
Open raw file ↗