Security Policy
Responsible disclosure and non-destructive testing only.
BioQCore follows a security-by-design posture for public infrastructure and welcomes responsible, non-destructive reports.
Version: 1.0.0-rc · Effective date: 2026-06-13
Responsible disclosure
Report suspected vulnerabilities to contact@bioqcore.org with the subject “Security Disclosure”. A dedicated security mailbox and PGP key are planned.
Allowed reports
- Broken access controls in public assets.
- Cross-site scripting or injection risk in public code.
- Security header weaknesses.
- Exposed secrets or sensitive files if found accidentally.
- Dependency or supply-chain risk.
Not allowed
- No destructive testing.
- No denial-of-service testing.
- No social engineering.
- No attempts to access patient data or private accounts.
- No persistence, malware, exfiltration or public disclosure before responsible handling.
Current public posture
- Static-first GitHub Pages site.
- No public patient data intake.
- Security headers configured where hosting supports them.
- GitHub workflow checks for HTML, links and OWASP ZAP baseline.
No bounty unless announced
No bug bounty program is active unless explicitly announced in a separate policy.