Skip to content

machine viewenglishraw: /security.mdbuild: d68074d2026-08-05T14:02Z

Security and responsible disclosure

Two things live on this page: how to report a security problem to us, and how security is agreed when we work inside a client’s systems. Anything specific to one project — controls, evidence, access — is reviewed during diligence, not published here.

Before we get access

Which repositories, infrastructure, and accesses Bleu will touch is defined per engagement — there is no standard setup. Before granting anything, you can go through the proposed setup with us and see which controls apply to your work, and which gaps remain.

What you can inspect

During diligence, and where the client allows it, we can show evidence from the project itself: repository settings, delivery checks, access records, dependency scans, handoff procedures. What we show from one project is evidence about that project — not a claim about every project.

Security is shared work

Bleu cannot deliver security alone. The outcome depends on your environment, the access you give us, and the controls both teams run. The contract should say who is responsible for what, who to call in an incident, and which of your policies apply to us.

Found a security problem?

Email security@bleu.builders about this website, our public code, or a system Bleu operates. In the first message, please leave out credentials and working exploit details, and don’t access personal data or disrupt a service to prove the point. We confirm receipt and agree on next steps with you.

Machine-readable contact: /.well-known/security.txt

SECURITY

Security and responsible disclosure

Two things live on this page: how to report a security problem to us, and how security is agreed when we work inside a client’s systems. Anything specific to one project — controls, evidence, access — is reviewed during diligence, not published here.

Before we get access

Which repositories, infrastructure, and accesses Bleu will touch is defined per engagement — there is no standard setup. Before granting anything, you can go through the proposed setup with us and see which controls apply to your work, and which gaps remain.

What you can inspect

During diligence, and where the client allows it, we can show evidence from the project itself: repository settings, delivery checks, access records, dependency scans, handoff procedures. What we show from one project is evidence about that project — not a claim about every project.

Security is shared work

Bleu cannot deliver security alone. The outcome depends on your environment, the access you give us, and the controls both teams run. The contract should say who is responsible for what, who to call in an incident, and which of your policies apply to us.

Found a security problem?

Email security@bleu.builders about this website, our public code, or a system Bleu operates. In the first message, please leave out credentials and working exploit details, and don’t access personal data or disrupt a service to prove the point. We confirm receipt and agree on next steps with you.

Machine-readable contact: /.well-known/security.txt