Trust note 03

Security

Burnbook treats evidence integrity, tenant isolation, and transcript privacy as product requirements.

Security boundary

No “unhackable” claims

A future Security Practice passport will describe evidence of secure engineering habits. It cannot guarantee that a person or application is secure, and absence of evidence is not evidence of poor practice.

Report a vulnerability

Give us a safe first contact

Send suspected vulnerabilities to security@burnbook.dev. Do not include secrets, private transcripts, customer repository content, or destructive proof-of-concept data in the first message.

Include the affected surface, expected impact, reproduction prerequisites, and a safe description of the behavior. Burnbook will coordinate a secure channel if sensitive evidence is required.

Priorities

What receives urgent treatment