Security Policy
Last updated: June 30, 2026
1. Security Practices
- TLS encryption for data in transit.
- Access-controlled infrastructure and admin operations.
- Authentication, ownership checks, rate limits, and policy enforcement for protected routes and APIs.
- Audit logging for privileged operational actions.
- Payment processing through Stripe so Beeprd does not store full card numbers.
- Privacy-aware defaults and field-level visibility controls where supported by the product.
2. User Responsibilities
Keep credentials, devices, passkeys, email accounts, sessions, and recovery paths secure. Use accurate account information, avoid sharing sessions, review links before clicking, and notify Beeprd promptly if you suspect unauthorized account access or malicious activity.
3. Responsible Disclosure
If you discover a vulnerability, email security@beeprd.com. Do not access, modify, destroy, or exfiltrate data; do not disrupt service; and do not publicly disclose the issue before Beeprd has had a reasonable opportunity to investigate.
4. No Bug Bounty Promise
Beeprd does not currently operate a paid bug bounty program. We appreciate responsible reports but do not guarantee compensation unless separately agreed in writing.
5. No Perfect Security Guarantee
Beeprd uses reasonable safeguards, but no internet service, account, device, transmission, third-party provider, or storage system can be guaranteed completely secure. Beeprd is not responsible for user misconduct, compromised user credentials, third-party provider failures, or malicious activity outside Beeprd's reasonable control.
6. Incident Response
Beeprd investigates security reports, prioritizes remediation based on severity, preserves relevant records where appropriate, and may notify affected users, providers, authorities, or regulators when required by law or necessary to protect users and the platform.