Security

Security and Responsible Disclosure

Report vulnerabilities or data-protection concerns privately so the team can investigate before details are shared publicly. This Nederlands page uses the same launch-approved content structure while final legal translation review is pending.

Report a security issue

Email admin@dancing-bee.com with subject "Security report" and include affected URL, account, device, reproduction steps, and impact.

Do not access other users data, run destructive tests, or publicly disclose an issue before we have had time to investigate.

Security posture

The backend uses HTTPS, JWT/refresh token controls, Firebase verification paths, Google Secret Manager, MongoDB, rate limits, audit logs, and redaction for sensitive diagnostics.

Production secrets must never be stored in GitHub, local repo files, public pages, or reviewer notes.