Love and Bliss (LAB) — Research · Publish · Flourish

Security

Security and responsible disclosure

If you have found a weakness in our platform, we want to hear from you first — and we will not pursue you for telling us.

Reporting a concern

Email info@loveandbliss.org with the subject line “Security report”. Please include what you found, the URL or request involved, and how to reproduce it. We aim to acknowledge reports within three working days.

Please do not access, modify or download other people's data, run denial-of-service or spam tests, or use social engineering against our staff. Give us reasonable time to fix an issue before publishing it.

How we protect information

  • All traffic is served over HTTPS, with HTTP requests redirected to HTTPS.
  • Access is decided per record by role, so signed-in users reach only the records their role permits.
  • Governance-owned fields (such as enrolment status and eligibility decisions) cannot be set by the record owner.
  • Governance events are written to an append-only, hash-chained audit history, and the chain is verified as part of our release checks.
  • Automated governance checks run on every change and block release when a rule fails.
  • Participant identities are separated from research records, with re-identification restricted to the principal investigator.

Site classification

LOVE AND BLISS (LAB) is a research and publishing organisation. If a network filter at your institution has categorised loveandbliss.org incorrectly, ask your IT team to re-categorise it as education or research, and contact us if you would like supporting information to include with that request.

Related pages

See our privacy notice and terms of use. A machine-readable contact is published at /.well-known/security.txt.