BioQCoreTrust-first research infrastructure
Security Policy

Responsible disclosure and non-destructive testing only.

BioQCore follows a security-by-design posture for public infrastructure and welcomes responsible, non-destructive reports.

Version: 1.0.0-rc · Effective date: 2026-06-13

Responsible disclosure

Report suspected vulnerabilities to contact@bioqcore.org with the subject “Security Disclosure”. A dedicated security mailbox and PGP key are planned.

Allowed reports

  • Broken access controls in public assets.
  • Cross-site scripting or injection risk in public code.
  • Security header weaknesses.
  • Exposed secrets or sensitive files if found accidentally.
  • Dependency or supply-chain risk.

Not allowed

  • No destructive testing.
  • No denial-of-service testing.
  • No social engineering.
  • No attempts to access patient data or private accounts.
  • No persistence, malware, exfiltration or public disclosure before responsible handling.

Current public posture

  • Static-first GitHub Pages site.
  • No public patient data intake.
  • Security headers configured where hosting supports them.
  • GitHub workflow checks for HTML, links and OWASP ZAP baseline.

No bounty unless announced

No bug bounty program is active unless explicitly announced in a separate policy.