Responsible reporting
Security policy
Report a suspected vulnerability without including passwords, private keys, identity documents or other sensitive user data.
The editorial priority is evidence-led review: current fee sources, product boundaries, security workflow and visible correction dates instead of a single marketing score. Readers should document their residency, funding currency, onboarding entity and product-specific restrictions. The primary platform scope is Bybit. For a Bybit-focused review, distinguish spot execution from perpetual-contract costs, include funding and liquidation mechanics, and verify the legal account entity plus withdrawal safeguards before trading. This guide records the source date and treats the logged-in account screen as the final authority for fees.
Contact
Use security@bybitreview2026.com. This address must be configured before production deployment.
Scope
Reports may cover the static site, redirects, scripts, headers and domain configuration. Exchange systems and affiliate destinations are outside this site's control.
Testing limits
Do not perform denial-of-service testing, social engineering, credential attacks, automated account creation or destructive testing.
Safe evidence
Provide the affected URL, observed behavior, reproduction steps and a minimal non-sensitive proof.