Skip to content
Documentation Portal →

Reporting a security issue

If you have found a vulnerability in a bydynamics app or in the support platform, please tell us privately first. We would rather hear it from you than read about it, and we will work with you on a fix and on when it becomes public.

How to report

Email support@bydynamics.com with SECURITY in the subject line.

Please include:

  • Which app or service, and which version
  • What an attacker could do — the impact, not only the mechanism
  • The steps to reproduce it
  • Anything you need from us to demonstrate it

If you would like to encrypt the report, say so in a first message and we will arrange a key.

Please do not open a support issue for this

A support issue is visible to everyone in your organisation with a portal account, and it enters our normal triage. Neither is right for a vulnerability that is not yet fixed.

What we ask of you

  • Give us time to fix it before you publish. We will agree a date with you rather than impose one
  • Do not access, modify or delete data that is not yours. If you reach somebody else's data while demonstrating an issue, stop and tell us what you saw — that itself is the finding
  • Do not run denial-of-service tests, spam, or social engineering against us, our customers, or our suppliers

What we will do

  • Acknowledge your report within five working days, to a person, not an autoresponder
  • Tell you whether we can reproduce it, and what we think the severity is
  • Keep you updated while we fix it, and tell you when it ships
  • Credit you when it becomes public, if you want to be credited

We do not run a paid bug bounty.

If you report in good faith

We will not pursue or support legal action against anyone who reports a vulnerability to us in good faith, follows the guidance above, and gives us a reasonable chance to fix it before publishing.

This is not a licence to access other people's data — it is a commitment that finding and reporting a genuine flaw is something we treat as help, not as an attack.

Out of scope

Reports about the following are usually already known and not treated as vulnerabilities:

  • Missing security headers with no demonstrated impact
  • Results from an automated scanner, unpaired with a working exploit
  • Vulnerabilities in Microsoft Dynamics 365 Business Central itself — report those to Microsoft
  • Social engineering of our staff or customers

Reporting an issue in Business Central itself

Our apps run inside Business Central, which is Microsoft's. If the flaw is in the platform rather than in our code, the Microsoft Security Response Centre is the right place, and they will move faster on it than we can.