Cyber Security
Responsible testing and disclosure.
Last updated: 21 September 2026
Brightbyte IT Solutions FZ-LLC provides cyber security and operational security services alongside its software and systems work. Security testing is intrusive by nature, so the terms under which we do it are set out here in plain terms — for clients, for the owners of systems we are asked to look at, and for anyone who wants to report a problem in our own.
1. What our cyber security work covers
Our engagements fall into four areas:
- Exposure and exploitability assessment. Establishing what of a client's infrastructure is reachable, and determining whether a given weakness is genuinely exploitable in their environment — so remediation is prioritised by real risk rather than by severity score alone.
- Vulnerability review and validation. Reviewing client code and configuration for security defects, and confirming findings against systems the client owns before they are reported, so that what we hand over is verified rather than theoretical.
- Detection engineering and incident support. Writing and tuning the rules and logging that would reveal an intrusion, and analysing suspicious files, scripts and artefacts recovered from client environments to establish what they do and how far they reached.
- Phishing simulation and footprint reduction. Running authorised social-engineering exercises and awareness training, and reviewing what an outsider could learn about an organisation from public sources, so that exposure can be reduced.
Supporting all four, we develop and maintain our own testing tooling — enumeration, scanning and validation scripts. That tooling is written and exercised in a laboratory environment built from hardware and virtual machines we own outright, and is proven there before it is ever pointed at a client system. It stays internal to our practice; section 3 sets out what that means.
2. Authorisation
We test only what we have been authorised in writing to test. Before any engagement begins:
- A scope of work and rules of engagement are signed by the party that owns or demonstrably controls the systems in question.
- In-scope assets are listed explicitly. Anything not listed is out of scope, including third-party infrastructure, shared hosting neighbours, and upstream providers.
- A testing window is agreed, together with a named contact who can be reached during it.
- Where a client's systems are hosted or operated by a third party, it is the client's responsibility to obtain that provider's permission, and we ask for evidence of it.
We decline work where ownership or authority over the target cannot be established. We do not accept engagements against systems belonging to someone other than the party instructing us.
3. Conduct during an engagement
- Testing is non-destructive by default. Anything with a material risk of disruption or data loss is proposed, explained, and agreed separately before it is attempted.
- We take the minimum data needed to demonstrate a finding. Where access to sensitive records is proven, it is proven by sample, not by extraction.
- If we encounter evidence of a pre-existing compromise, we stop, secure what we have, and notify the client's named contact immediately.
- Findings, evidence and engagement artefacts are held only for the period agreed in the scope of work, then destroyed. Reports go to the client and to nobody else.
- Tooling developed for an engagement stays internal. We do not publish, sell or supply exploit code to third parties.
4. What we do not do
Some work is outside our practice regardless of who is asking or what is offered. We do not:
- develop ransomware, wipers, or any tooling whose purpose is to deny a victim access to their own systems or data;
- build or operate capability for mass collection or exfiltration of data;
- test, probe or attack systems without documented authorisation from their owner;
- take work whose object is surveillance of individuals who have not consented to it;
- sell or broker vulnerabilities, exploits or access to third parties.
If an enquiry falls into any of the above we will say so and decline it, rather than negotiate the scope.
5. Reporting a vulnerability in our systems
If you believe you have found a security issue in brightbyte-solutions.com or in any system operated by Brightbyte IT Solutions, we would like to hear about it. Write to info@brightbyte-solutions.com with the subject line Security report, and include enough detail for us to reproduce the issue — the affected URL or component, the steps involved, and the impact as you understand it.
We will acknowledge your report within two business days and keep you informed while we investigate. We do not operate a paid bounty programme, but we will credit you if you would like to be named.
Safe harbour. We will not pursue or support legal action against anyone who reports an issue in good faith, provided they stay within the same limits we hold ourselves to: no accessing, modifying or exfiltrating data belonging to others, no degradation of the service, no social engineering of our staff or clients, and no disclosure to third parties before we have had a reasonable opportunity to fix it. Please give us 90 days before publishing.
6. Contact
Brightbyte IT Solutions FZ-LLC, registered in the Ras Al Khaimah Economic Zone at CWEP5935, Compass Building, Al Shohada Road, Al Hamra Industrial Zone-FZ, Ras Al Khaimah, United Arab Emirates. Engagements are delivered from Dubai, UAE. Email info@brightbyte-solutions.com. Machine-readable contact details are published at /.well-known/security.txt.