Coordinated security reporting
Report a potential security issue safely.
Email admin@ironhand.org with the affected URL or component, a concise reproduction, impact, and a safe way to contact you. Do not include live customer content, credentials, government identifiers, or destructive proof.
Scope
GrantPilot-owned web applications, APIs, and deployment endpoints are in scope. Social engineering, physical attacks, denial of service, automated high-volume scanning, third-party services, and access to another person’s data are out of scope.
Safe research boundaries
Use only accounts and synthetic data you control. Stop immediately if you encounter customer or confidential data. Do not persist access, alter records, interrupt service, send email, upload malware, or bypass provider terms. Good-faith research within these boundaries will not be pursued as an attack by GrantPilot.
Response process
We target acknowledgement within three U.S. business days, initial validation within ten business days, and a status update at least every seven business days while a validated issue remains open. Remediation timing depends on severity and safe deployment requirements.
Disclosure and rewards
Coordinate public disclosure with us until a fix is available or an agreed date is reached. No monetary bounty is currently offered. We may credit reporters who request recognition and comply with this process.
Sensitive report handling
Ordinary email is not appropriate for secrets or customer evidence. Send only the minimum reproduction needed and request an approved secure exchange channel for sensitive supporting material.