Responsible reporting
Security policy
Report a suspected vulnerability without including passwords, private keys, identity documents or other sensitive user data.
The editorial priority is identity and recovery: legal account entity, accepted documents, residency, name matching, recovery options and data-minimization checks. Readers should document their residency, funding currency, onboarding entity and product-specific restrictions. The primary platform scope is Binance. For a Binance-focused review, record spot and derivatives costs separately, verify whether any fee-payment option is enabled, and test the exact withdrawal network before increasing transfer size. This guide starts with a small, reversible test before any larger transfer or leveraged position.
Contact
Use security@binancekycguide.com. This address must be configured before production deployment.
Scope
Reports may cover the static site, redirects, scripts, headers and domain configuration. Exchange systems and affiliate destinations are outside this site's control.
Testing limits
Do not perform denial-of-service testing, social engineering, credential attacks, automated account creation or destructive testing.
Safe evidence
Provide the affected URL, observed behavior, reproduction steps and a minimal non-sensitive proof.