Security
Vulnerability Disclosure Policy
sgoguide.com · security@sgoguide.com
Report it here
Email security@sgoguide.com with enough detail to reproduce the issue — a URL, the steps, and what you saw. If you believe you have accessed someone else’s donation, application, or student record, say so first and stop there; we will take it from your description rather than ask you to prove it again.
What we commit to
- We acknowledge every report within two business days.
- We tell you what we found and whether we are fixing it, and we let you know when the fix ships.
- We will credit you by name if you want the credit, and stay quiet about you if you do not.
- We do not run a paid bounty program. We would rather say that plainly than imply one.
Safe harbor
If you make a good-faith effort to follow this policy, we will not pursue legal action against you or ask anyone else to. Good faith means: you stop as soon as you have confirmed a problem, you access only accounts and data that are your own or that we have given you for testing, you do not modify or delete anything that is not yours, and you give us a reasonable chance to fix the issue before telling anyone else about it.
Please do not
- Run denial-of-service, load, or brute-force testing against our systems. This platform serves families in the middle of scholarship applications.
- Use social engineering, phishing, or physical access attempts against our staff, our partner schools, or their families.
- Access, download, or retain another person’s records. One screenshot proving the exposure is enough; a database dump is not research.
- Test third-party services we depend on — payments, authentication, email, hosting. Report those to the vendors directly, and tell us so we can follow up.
Out of scope
Reports produced only by an automated scanner with no demonstrated impact, missing hardening headers on pages that hold no data, rate-limiting on unauthenticated read-only endpoints, software version disclosure, and issues that require an already-compromised device or a browser we do not support. We would still rather see a borderline report than miss a real one — if you are unsure, send it.
Machine-readable contact
The same contact details are published at /.well-known/security.txt per RFC 9116. For how we handle personal information generally, see our Privacy Policy.