Legal & Trust Center

Responsible Disclosure Policy

How to report a suspected vulnerability safely.

Version
1.0
Effective date
17 August 2026
Last updated
17 August 2026
Document owner
the Groundmaster project, with responsibility assigned to its legal and compliance function
Applicable jurisdiction
Portugal, European Union
Permanent URL
https://www.groundmaster.pt/legal/disclosure
We welcome good-faith security research. Please report findings privately and give us a reasonable opportunity to remediate before any public disclosure.

1.How to report

Send reports to groundmaster.web@gmail.com or groundmaster.web@gmail.com with a clear description, the steps required to reproduce the issue, the affected area of the Platform, the potential impact, and any supporting evidence. Please avoid including third-party personal data in your report.

2.What we ask of you

  • act in good faith and avoid privacy violations, data destruction and service disruption;
  • use only your own test accounts and data; never access, modify or retain another organisation's data;
  • stop immediately if you encounter personal data, and report it rather than continuing to explore;
  • do not run denial-of-service, load, spam or social-engineering tests, and do not attempt physical access;
  • do not use automated scanning that degrades availability;
  • give us reasonable time to remediate before disclosing publicly, and coordinate the timing with us.

3.In scope

The public website, the authenticated application, and the server interfaces used by them. Findings such as authentication or authorisation bypass, permission or tenancy separation flaws, injection, insecure direct object references, sensitive data exposure, and insecure configuration are of particular interest.

4.Out of scope

  • reports generated solely by automated tools without demonstrated impact;
  • missing hardening headers or configuration suggestions with no exploitable impact;
  • issues requiring physical access, a rooted or compromised device, or unrealistic user interaction;
  • vulnerabilities in third-party services outside our control, which should be reported to that provider;
  • volumetric or availability testing of any kind.

5.Our commitments

  • acknowledge receipt of your report within a short period;
  • triage and assess severity, and keep you informed of progress;
  • remediate valid findings on a timeline proportionate to severity;
  • credit reporters who wish to be acknowledged, once remediation is complete;
  • not pursue legal action against researchers who follow this policy in good faith.

6.No bounty programme

We do not currently operate a paid bug bounty programme. Reports are handled on the basis described above, and we are grateful for responsible research.

Change history

VersionDateChange
1.017 August 2026Initial responsible disclosure policy.
Contact

Questions about this document can be sent to groundmaster.web@gmail.com. Formal legal, privacy, security and regulatory requests should follow the routes described in the legal requests page. Fields shown as bracketed placeholders are pending confirmation by the operating legal entity and do not constitute a statement of fact.

Related documents