Security

How to report a security issue, and what we do about it.

Report a vulnerability

If you find a real security issue in Groundwork, email david@groundworkscan.com with what you found and how to reproduce it. We read every report and will follow up.

What we ask

Please don't access, modify, or exfiltrate data beyond what's needed to demonstrate the issue, and don't publicly disclose before we've had a reasonable chance to fix it. We won't pursue legal action against a good-faith report made this way.

No bug bounty, real acknowledgment

We're a small operation and don't currently run a paid bug bounty program. A real, valid report is still worth your time to us - we'll fix it and, if you'd like, credit you when we're able to.

What we already do

Dependency vulnerabilities are monitored automatically (GitHub Dependabot alerts) and checked on every change (a CI dependency audit). We don't claim a full third-party security audit has been done - if you find something we missed, that's exactly what this page is for.

Related

A machine-readable version of this contact is also published at /.well-known/security.txt per RFC 9116. See also our Privacy Policy and Terms.