RESPONSIBLE DISCLOSURE POLICY – LittleBigCampus
Last updated: September 11, 2026
Operator: Little Big Campus
1. Introduction
Little Big Campus is committed to ensuring the security of its platform and users. We recognize the key role played by security researchers and ethical hackers in identifying security vulnerabilities. This policy defines the framework under which we invite you to collaborate with us in a responsible manner.
2. Scope
This policy applies to the following assets:
- The main website https://www.littlebigcampus.com
- All active subdomains
- APIs associated with the operation of the platform
3. Authorized Activities
In the context of responsible security research, you are authorized to:
- Passively analyze the site and its public resources;
- Test for vulnerabilities against your own user account;
- Identify and report any security issue affecting the platform or its users.
4. Strictly Prohibited Activities
The following actions are strictly prohibited:
- Accessing, modifying, or exfiltrating data belonging to other users;
- Executing Denial of Service (DoS/DDoS) attacks;
- Publishing, sharing, or exploiting a vulnerability prior to its remediation (no premature public disclosure);
- Conducting social engineering attempts against Little Big Campus members or staff;
- Installing backdoors, malware, or any malicious payload;
- Testing third-party systems not explicitly listed in the scope above.
5. How to Report a Vulnerability
Send your vulnerability report to:
Please encrypt your message using our OpenPGP public key available at the following location:
OpenPGP Public Key (keys.openpgp.org)
Your report should include:
- A clear and detailed description of the vulnerability;
- Step-by-step instructions to reproduce the issue;
- An estimate of the potential impact;
- Any relevant screenshots or proof-of-concept material.
6. Our Commitments to You
In exchange for a responsible report adhering to this policy, Little Big Campus commits to:
- Acknowledge receipt of your report within 48 business hours;
- Confirm the vulnerability and provide status updates within 7 days;
- Remediate the vulnerability within a reasonable timeframe proportional to its severity;
- Waive legal action against you, provided you have fully complied with the terms of this policy (Safe Harbor);
- Publicly acknowledge your contribution on our acknowledgments page, if you wish.
7. Coordinated Disclosure
We adhere to the principle of coordinated vulnerability disclosure: we ask that you allow us a 90-day period to resolve the vulnerability before any public disclosure. If we are unable to meet this timeline, we will inform you and negotiate a reasonable extension with you.
8. Contact and security.txt File
Our security.txt file, fully compliant with the RFC 9116 standard, is hosted at the following URL:
https://www.littlebigcampus.com/.well-known/security.txt
This policy is subject to updates. Please review this page periodically to ensure you remain familiar with the current version.