Skip to content

Security

How we protect your account

A statement of the practices we operate today. We describe what we do, not what we aspire to, and we will not claim a certification we have not completed.

Practices in place

The controls behind every BMT session.

Encryption in transit and at rest

All traffic is served over TLS 1.3 with HSTS. Stored account data is encrypted at rest by the managed platform.

Least-privilege access

Internal access to production data is role-scoped, reviewed, and logged. No shared credentials.

Secure by default frontend

A strict content policy, no inline third-party trackers before consent, and no personal data written to local storage beyond your own device preferences.

Change control

Every deployment is reviewed and reversible, with an audit trail from change to release.

Report a vulnerability

We welcome good-faith research and we will not pursue researchers who follow this policy.

  1. 1. Tell us privately. Email security@bmt.tv with steps to reproduce. Please do not open a public issue first.
  2. 2. Give us room. Do not access, modify, or delete data that is not yours, and do not run tests that degrade service for viewers.
  3. 3. What happens next. We acknowledge within three working days, share a remediation plan within ten, and credit you on request once the fix ships.

Account and data questions belong on the privacy policy page, and general enquiries on contact.