Security & Responsible Disclosure
Blue Ridge Systems Consulting takes the security of its public websites, infrastructure, dashboards, forms, and related systems seriously.
Reporting a security concern
If you believe you have found a security issue affecting a Blue Ridge public web property, please report it by email: info@blueridgesystems.us
Helpful details to include
When reporting a suspected issue, please include:
- The affected URL or service
- A short description of the issue
- Steps needed to reproduce it, if safe to provide
- Screenshots or logs, if helpful
- Your contact information if you want a response
Responsible disclosure expectations
Blue Ridge welcomes good-faith reports, but does not authorize intrusive, disruptive, or unsafe testing.
Please do not:
- Access, modify, delete, or copy data that is not yours
- Attempt persistence or privilege escalation
- Disrupt service availability
- Run aggressive automated scanning
- Test against non-public systems
- Attempt phishing, social engineering, or physical attacks
- Publicly disclose a suspected issue before Blue Ridge has had a reasonable opportunity to review it
No bounty program
Blue Ridge does not currently operate a public bug bounty program. Submitting a report does not create an obligation for payment, reward, employment, or formal engagement.
Security.txt
Blue Ridge may also publish a security.txt file to provide a standard place for security contact information. The human-readable guidance on this page applies alongside any published security.txt file.
Good-faith handling
Blue Ridge will review good-faith reports and work to address confirmed issues based on severity, risk, and available resources.
Contact
Security reports and questions can be sent to info@blueridgesystems.us.
Last updated: August 26, 2026
Return to Blue Ridge Systems