Vulnerability Disclosure Policy
We take security seriously and welcome reports from security researchers acting in good faith. If you believe you've found a vulnerability in GrantMe, we want to hear about it.
How to report
Email security [at] grantme.au with a description of the issue, steps to reproduce, and any relevant URLs or screenshots. We acknowledge reports within 2 business days.
What we ask
- Give us reasonable time to investigate and fix the issue before any public disclosure.
- Don't access, modify or delete data that isn't yours.
- Don't degrade the service. No denial of service, no spam, and no social engineering of staff or schools.
- Don't run automated scanners against production.
- Stop and report immediately if you encounter personal data.
What we promise
- We won't pursue legal action against researchers who act in good faith within this policy.
- We'll keep you informed of progress.
- We'll credit you, with your permission, once the issue is fixed.
Out of scope
- Findings from automated tools without a working proof of concept.
- Issues in third-party services we don't control.
- Clickjacking on pages with no sensitive actions.
- Missing security headers on non-sensitive pages.
- Volumetric denial of service.
This policy applies to grantme.au and app.grantme.au.