Trust · Draft
Vulnerability Disclosure Policy
How to report a security vulnerability in StGatherly, and what you can expect from us. This is a draft for review and is not yet in force.
Last updated: Draft, not yet published
01Introduction
We take the security of StGatherly and the data churches entrust to us seriously. If you are a security researcher and believe you have found a vulnerability, we welcome your report and will work with you to understand and resolve it. This policy explains how to report an issue and what you can expect from us.
02How to report
Please email hello@stgatherly.com [CONFIRM: set up a dedicated security@stgatherly.com mailbox] with:
- A clear description of the issue and its potential impact.
- Steps to reproduce it, including any proof-of-concept.
- The affected URL, page, or component, and any relevant configuration.
03Guidelines for researchers
When investigating, please:
- Act in good faith to avoid privacy violations, data loss, and service disruption.
- Only interact with accounts you own or have explicit permission to test. Never access, modify, or delete another church’s data.
- Do not run automated scanning that degrades the Service, and do not perform denial-of-service testing.
- Give us a reasonable opportunity to resolve the issue before disclosing it publicly.
- Do not use, retain, or share any data you encounter.
04Our commitment (safe harbour)
If you make a good-faith effort to comply with this policy during your research, we will:
- Regard your activity as authorised and not pursue or support legal action against you for it.
- Acknowledge your report and work with you to understand and resolve the issue promptly.
- Where you wish, credit you once the issue is fixed.
StGatherly does not currently operate a paid bug bounty programme.
05Out of scope
Reports that typically fall outside this policy include social engineering, physical attacks, spam or best-practice suggestions without a demonstrable security impact, and vulnerabilities in third-party services we do not control. If in doubt, report it and we will let you know.