Security
Security and vulnerability reporting.
Safeguards for the site and a route for responsible reports.
Policy
How this works.
Current safeguards
The public site uses HTTPS. Workspace passwords are hashed, sessions use secure HTTP-only cookies, writes use CSRF protection and database operations use prepared statements. Roles limit access to private records.
Report a concern
Email hello@bcaligned.co.uk with “Security report” in the subject, the affected URL, a concise reproduction and the potential impact. Do not include other users’ data or continue probing after finding a material issue.
Handling
We will investigate, contain and correct a verified issue, and inform affected people where required. Do not disclose a live exploit publicly before giving us a reasonable opportunity to respond.
Operator: BC Aligned · Last reviewed 25 September 2026 · Contact us