Curiosity security

Defensive work, inside the lines.

Curiosity Limited operates learning software, product sites, and API-backed services. Security work is internal-only, human-reviewed, and limited to systems we own, operate, or are explicitly authorized to assess.

curiositybyade.com/trust-security
Internal AppSec Owned scope
Access boundaryApproved internal users only
Set
Review targetCode, APIs, config, tests
Scoped
Human reviewFindings checked before changes ship
Required

Only systems we own or are authorized to test.

Curiosity security reviews cover Curiosity-operated websites, application repositories, APIs, deployment configuration, and local or staging environments.

Third-party systems are out of scope unless Curiosity has explicit written authorization to assess them.

Public services

curiositybyade.com, learn.curiositybyade.com, joinonair.com, and related Curiosity product pages.

Source and configuration

Curiosity-owned GitHub repositories, route handlers, templates, tests, deployment settings, and redacted config.

Local and staging

Controlled non-production environments where review can happen without affecting live users.

Code reviewAuthentication, authorization, sessions, CSRF, forms, templates, and API permissions.
Config reviewSecurity headers, CSP, production settings, dependency risk, and secret-handling boundaries.
Patch validationFinding triage, remediation plans, regression tests, and human approval before release.
Privacy controlsData export, deletion, retention limits, and minimum necessary data sharing with model providers.
Disclosure routeSecurity reports go to [email protected], with acknowledgement and follow-up targets.
No certification claimCuriosity is not currently claiming SOC 2, ISO 27001, Cyber Essentials, or equivalent certification.

Built for defensive AppSec, not theatre.

Internal security work focuses on vulnerability identification, threat modelling, dependency and configuration review, remediation validation, and incident-readiness for Curiosity-owned systems.

Security tooling output is advisory. Findings are checked by a human before they become accepted risk, patches, production changes, or external disclosures.

Internal-only means internal-only.

Allowed: approved Curiosity users reviewing owned or explicitly authorized systems for defensive security purposes.

Not allowed: unauthorized third-party testing, availability-impacting scans, brute force, credential attacks, social engineering, exploit development for misuse, or customer-facing access to privileged security tools.

Found something? Tell us plainly.

Please include the affected URL, steps to reproduce, potential impact, and relevant screenshots or logs. Avoid automated scanning, brute-force attempts, social engineering, or anything that could affect availability for users.

Email security reports to [email protected]. Privacy questions can go to [email protected].

Email Curiosity