Security Policy
Responsible disclosure and non-destructive testing only.
BioQCore follows a security-by-design posture for public infrastructure and welcomes responsible, non-destructive reports.
Version: 1.0.2-rc.1 · Last reviewed: 2026-08-26
Responsible disclosure
Report suspected vulnerabilities to contact@bioqcore.org with the subject “Security Disclosure”. A dedicated security mailbox and PGP key are planned.
Receipt of a report does not grant authorization to access systems or data beyond the reporter's existing lawful access. Testing must remain non-destructive and within the boundaries stated on this page.
Relevant reports
- Broken access controls in public assets.
- Cross-site scripting or injection risk in public code.
- Security header weaknesses.
- Exposed secrets or sensitive files if found accidentally.
- Dependency or supply-chain risk.
Not allowed
- No destructive testing.
- No denial-of-service testing.
- No social engineering.
- No attempts to access patient data or private accounts.
- No persistence, malware or deliberate exfiltration.
- No public disclosure of unresolved vulnerabilities before responsible handling.
Current public posture
- Static-first GitHub Pages site.
- No public patient-data intake.
- Security-header policy is maintained in the repository and must be verified against the active hosting/CDN layer.
- Repository workflows include HTML validation, link checking and OWASP ZAP baseline checks.
No bug bounty currently active
No bug bounty, reward or safe-harbor program is currently offered unless explicitly published in a separate current policy.