Trust note 03
Security
Burnbook treats evidence integrity, tenant isolation, and transcript privacy as product requirements.
Security boundary
No “unhackable” claims
A future Security Practice passport will describe evidence of secure engineering habits. It cannot guarantee that a person or application is secure, and absence of evidence is not evidence of poor practice.
Report a vulnerability
Give us a safe first contact
Send suspected vulnerabilities to security@burnbook.dev. Do not include secrets, private transcripts, customer repository content, or destructive proof-of-concept data in the first message.
Include the affected surface, expected impact, reproduction prerequisites, and a safe description of the behavior. Burnbook will coordinate a secure channel if sensitive evidence is required.
Priorities
What receives urgent treatment
- Cross-account access or modification.
- Credential, signing-key, or future encryption-key exposure.
- Unauthorized transcript or private GitHub disclosure.
- Remote execution or workspace access without explicit approval.
- Evidence forgery that materially compromises public rankings.