Pre-launch security statement. Publish a verified security contact and disclosure process before production release.
Platform safeguards
Encryption in transit, protected secrets, least-privilege access, secure development practices and monitored production systems form the baseline.
Multi-factor access for administrators
Dependency and code review
Rate limits and abuse detection
Backups and recovery testing
Responsible disclosure
Security researchers should be able to report vulnerabilities privately through security@bluecampus.app after that inbox and acknowledgement process are active.
What to include
Provide the affected area, clear reproduction steps, impact and any supporting evidence. Do not access other people’s data or disrupt the service.