Report a security issue
Protecting our users' data is our top priority. Security is not an afterthought but part of our architecture, our operations, and how we build software. If you still find a vulnerability, help us fix it quickly.
This covers anything that could compromise user data or affect the service, including phishing attempts targeting Grounds Up or our users. The sooner we hear about it, the faster we can respond.
How we handle reports
We will not take legal action against anyone who reports vulnerabilities responsibly. As long as you act in good faith, do not access other people's data, and give us time to fix the issue, you are safe.
We will acknowledge your report within 48 hours and keep you informed about the progress. Every report is treated confidentially and stored only as long as needed to resolve the issue or as required by law.
Grounds Up is a free product. We do not run a bug bounty programme and do not offer monetary rewards for reports.
What we need from you
Our disclosure policy covers:
- app.grounds-up.coffee (application)
- grounds-up.coffee (website)
- Associated APIs and infrastructure under these domains
Third-party services we use (e.g. hosting providers) are not in scope. If you are unsure, just ask.
To help us investigate quickly, please include:
- Description of the issue
- Affected URL or component
- Timestamp and your time zone
- Steps to reproduce or debug information
- A way to reach you for follow-up questions
Contact
E-Mail: security@on-promise.cloud
Security.txt: security.txt
Frequently Asked Questions
Do you pay for reported vulnerabilities?
No. Grounds Up is a free product and we do not run a bug bounty programme. We appreciate every report and handle all submissions carefully.
What happens after I report an issue?
We acknowledge receipt within 48 hours, investigate the problem, and keep you updated on the progress. Once resolved, we let you know.
Can I report anonymously?
Yes. However, we recommend providing a way to reach you so we can follow up with questions. Without contact details, we cannot provide status updates.
Which systems are covered?
Our policy covers app.grounds-up.coffee, grounds-up.coffee, and associated APIs. Third-party services such as hosting providers are not in scope.