Currently the bprelease package can be exported and if taken out of organization , it can be imported to any environment across any organization which is against the IP rights of the original organization. It practically defies the definition of security compliance. There should be an option to password protect functionality or using RBAC to control the bprelease import within the same org only.