Coordinated security reporting

Report a potential security issue safely.

Email admin@ironhand.org with the affected URL or component, a concise reproduction, impact, and a safe way to contact you. Do not include live customer content, credentials, government identifiers, or destructive proof.

Scope

GrantPilot-owned web applications, APIs, and deployment endpoints are in scope. Social engineering, physical attacks, denial of service, automated high-volume scanning, third-party services, and access to another person’s data are out of scope.

Safe research boundaries

Use only accounts and synthetic data you control. Stop immediately if you encounter customer or confidential data. Do not persist access, alter records, interrupt service, send email, upload malware, or bypass provider terms. Good-faith research within these boundaries will not be pursued as an attack by GrantPilot.

Response process

We target acknowledgement within three U.S. business days, initial validation within ten business days, and a status update at least every seven business days while a validated issue remains open. Remediation timing depends on severity and safe deployment requirements.

Disclosure and rewards

Coordinate public disclosure with us until a fix is available or an agreed date is reached. No monetary bounty is currently offered. We may credit reporters who request recognition and comply with this process.

Sensitive report handling

Ordinary email is not appropriate for secrets or customer evidence. Send only the minimum reproduction needed and request an approved secure exchange channel for sensitive supporting material.

Evaluate the controlled workflow.

Review current limitations and release gates before using real customer data.

Review current availabilityView product tour