BioQCoreTrust-first research infrastructure
Security Policy

Responsible disclosure and non-destructive testing only.

BioQCore follows a security-by-design posture for public infrastructure and welcomes responsible, non-destructive reports.

Version: 1.0.2-rc.1 · Last reviewed: 2026-08-26

Responsible disclosure

Report suspected vulnerabilities to contact@bioqcore.org with the subject “Security Disclosure”. A dedicated security mailbox and PGP key are planned.

Receipt of a report does not grant authorization to access systems or data beyond the reporter's existing lawful access. Testing must remain non-destructive and within the boundaries stated on this page.

Relevant reports

  • Broken access controls in public assets.
  • Cross-site scripting or injection risk in public code.
  • Security header weaknesses.
  • Exposed secrets or sensitive files if found accidentally.
  • Dependency or supply-chain risk.

Not allowed

  • No destructive testing.
  • No denial-of-service testing.
  • No social engineering.
  • No attempts to access patient data or private accounts.
  • No persistence, malware or deliberate exfiltration.
  • No public disclosure of unresolved vulnerabilities before responsible handling.

Current public posture

  • Static-first GitHub Pages site.
  • No public patient-data intake.
  • Security-header policy is maintained in the repository and must be verified against the active hosting/CDN layer.
  • Repository workflows include HTML validation, link checking and OWASP ZAP baseline checks.

No bug bounty currently active

No bug bounty, reward or safe-harbor program is currently offered unless explicitly published in a separate current policy.