safety
Bible Grow Security and Vulnerability Disclosure Policy
Version 1.1 · Effective 11 September 2026
1. Security commitment
Bible Grow, operated by Etara Innovations Limited, applies reasonable administrative, technical, and organizational safeguards designed to protect confidentiality, integrity, and availability. Security is an ongoing process, and no online service can guarantee absolute protection.
2. Security principles
Bible Grow follows risk-based access control, least privilege, secure authentication, logging, monitoring, backup, vulnerability remediation, responsible disclosure, and continuous improvement.
3. Account and data security
Bible Grow limits access to personal information to authorized personnel and systems with a legitimate operational need. Users must protect their credentials and devices and promptly report suspected compromise.
4. Secure development and operations
Security is considered during planning, development, review, testing, deployment, and maintenance. Bible Grow applies dependency updates, configuration review, access controls, and other controls appropriate to the Platform. Detailed configurations are not publicly disclosed where disclosure would create risk.
5. Incident response
Bible Grow investigates suspected incidents, contains harm, restores affected services, preserves appropriate evidence, and implements corrective action. Affected users and authorities are notified where required by applicable law.
6. Vulnerability reporting
Researchers and users may privately report suspected vulnerabilities to inquiries@biblegrow.org. Reports should identify the affected component, describe reproducible steps, explain the potential impact, and include only the minimum evidence necessary. Do not include personal data belonging to other users.
7. Safe-harbour conditions
Bible Grow will not pursue legal action against good-faith research that stays within this Policy, avoids privacy violations and service disruption, uses only accounts and data the researcher owns or is authorized to use, promptly reports the issue, allows reasonable time for remediation, and does not exploit the issue beyond what is necessary to demonstrate it. This statement does not authorize conduct prohibited by law or by third-party systems.
8. Out-of-scope testing
The following are not authorized: denial-of-service testing; social engineering; phishing; malware; physical attacks; accessing, modifying, deleting, or exfiltrating another person’s data; automated testing that materially degrades service; attacks on third-party providers; extortion; public disclosure before a reasonable remediation period; and testing that violates law.
9. Disclosure and remediation
Bible Grow acknowledges valid reports where practicable, assesses severity, and works toward remediation according to risk and operational constraints. Bible Grow does not promise a bounty or payment unless a separate written program expressly provides one. Researchers should coordinate public disclosure with Bible Grow.
10. Third-party services
Reports concerning an independent third-party service should be submitted to that provider unless the issue arises from Bible Grow’s configuration or integration. Bible Grow may coordinate with providers where appropriate.
11. User responsibilities
Users should use strong unique passwords, protect devices, install updates, avoid suspicious links, verify official communications, and report suspected fraud or compromise.
12. Contact and updates
Security reports and questions may be sent to inquiries@biblegrow.org. This Policy may be updated as security practices, law, and technology evolve. The current version is published at https://biblegrow.org.
This Policy is a public disclosure framework, not a technical security specification and not a guarantee that every risk is eliminated.