1. Purpose
This Policy explains the security principles followed by CyberQamus and how users or security researchers can report suspected vulnerabilities.
2. Security approach
CyberQamus applies security measures proportionate to the nature and maturity of the platform.
These may include:
- Supabase authentication
- Email verification
- Role-based access
- Row Level Security
- Restricted administrative functions
- Secure handling of API credentials
- Input validation
- Logging and audit trails
- Database backups
- Dependency and vulnerability reviews
- Secure development and testing practices
- Monitoring of authentication and application errors
Security controls will continue to develop as the platform grows.
3. Account security
Users should:
- Use a strong, unique password
- Protect access to their email account
- Avoid sharing login credentials
- Sign out from shared devices
- Report suspected unauthorised access
- Keep profile and contact information accurate
CyberQamus will never request a user’s password by email.
4. Access control
Public visitors receive read-only access to public terminology.
Authenticated contributors may access only the functions permitted to their accounts.
Administrative functions must be restricted to authorised administrators.
Access restrictions must be enforced through Supabase security rules and not only by hiding interface elements.
5. Data protection
CyberQamus aims to:
- Minimise the personal information collected
- Restrict access to personal and administrative data
- Protect authentication secrets
- Avoid exposing privileged keys in browser code
- Maintain audit information for important actions
- Use encrypted connections
- Review service-provider security settings
6. Vulnerability reporting
Security researchers and users are encouraged to report suspected vulnerabilities responsibly.
Reports should be sent to: security@cybergamus.org
Include where possible:
- Description of the issue
- Affected page or feature
- Steps to reproduce
- Potential impact
- Screenshots or technical evidence
- Suggested remediation
- Contact information for follow-up
Do not include unnecessary personal information or data belonging to other users.
7. Responsible testing rules
When testing or investigating CyberQamus:
- Do not access, alter, delete, or download another user’s information
- Do not use denial-of-service techniques
- Do not send spam
- Do not use automated testing that harms availability
- Do not perform social engineering
- Do not attempt physical attacks
- Do not publicly disclose an unresolved vulnerability
- Stop testing if sensitive information is accessed
- Report the issue promptly
Authorisation is limited to good-faith testing of publicly accessible CyberQamus systems owned or operated by the project.
Third-party services are outside scope unless explicitly stated otherwise.
8. What happens after a report
CyberQamus aims to:
- Acknowledge valid security reports
- Review and reproduce the issue
- Assess its impact and urgency
- Take reasonable corrective action
- Communicate with the reporter when practical
- Record material incidents and corrective actions
Response times may depend on the severity, complexity, and available project resources.
9. Recognition and rewards
CyberQamus does not currently operate a paid bug-bounty programme.
Recognition may be provided at the project’s discretion where:
- The report is original
- The researcher followed this Policy
- The issue created meaningful security risk
- Public recognition does not create additional risk
10. Security incidents
Where a security incident affects user information or platform operation, CyberQamus will investigate, contain, remediate, and document the incident.
Affected users or competent authorities will be informed where required by applicable law or where notification is reasonably necessary to reduce harm.
11. No guarantee of absolute security
CyberQamus works to reduce security risks, but no internet service can guarantee complete protection against every threat.
Users should report suspicious behaviour and maintain appropriate security over their own accounts.
12. Contact
Security reports: security@cybergamus.org
Privacy matters: privacy@cybergamus.org
General enquiries: contact@cybergamus.org