Vulnerability Disclosure Policy

We take security seriously and welcome reports from security researchers acting in good faith. If you believe you've found a vulnerability in GrantMe, we want to hear about it.

How to report

Email security [at] grantme.au with a description of the issue, steps to reproduce, and any relevant URLs or screenshots. We acknowledge reports within 2 business days.

What we ask

  • Give us reasonable time to investigate and fix the issue before any public disclosure.
  • Don't access, modify or delete data that isn't yours.
  • Don't degrade the service. No denial of service, no spam, and no social engineering of staff or schools.
  • Don't run automated scanners against production.
  • Stop and report immediately if you encounter personal data.

What we promise

  • We won't pursue legal action against researchers who act in good faith within this policy.
  • We'll keep you informed of progress.
  • We'll credit you, with your permission, once the issue is fixed.

Out of scope

  • Findings from automated tools without a working proof of concept.
  • Issues in third-party services we don't control.
  • Clickjacking on pages with no sensitive actions.
  • Missing security headers on non-sensitive pages.
  • Volumetric denial of service.

This policy applies to grantme.au and app.grantme.au.