Scope
This policy covers the public HBCU.ai website and its subdomains. It does not cover third-party sites we link to, such as university, agency, funder, or publisher websites — please report those to their owners.
How to report
Email HBCUAI@proton.me with the affected page address, a clear description of the issue, and the minimum steps needed to understand it. Please report in English where possible, and give us reasonable time to respond before any public disclosure.
Please avoid
Do not run automated scanning that degrades the service, attempt denial of service, access or modify data that is not yours, social-engineer anyone, or test physical security. Testing should stop as soon as a vulnerability is confirmed.
What to expect
We acknowledge reports by email, assess them, and fix confirmed issues as quickly as we reasonably can. We do not currently operate a paid bug-bounty program. We will not pursue good-faith researchers who follow this policy.
Machine-readable contact
Our contact details are also published at /.well-known/security.txt.