We value the security research community. If you believe you have found a security vulnerability in AramGRC, we want to hear from you and will work with you to resolve it.
Scope
In scope: the AramGRC website and platform at aramgrc.com and its subdomains.
Out of scope: third-party services we do not control, social engineering of our staff or users, physical attacks, and denial-of-service testing.
How to report
Email contact@aramgrc.com with: a clear description of the issue, the steps to reproduce it, the affected URL or component, and any supporting material (screenshots, logs, proof-of-concept).
Our commitment
- We will acknowledge your report within 3 business days.
- We will keep you informed as we investigate and remediate.
- We will not pursue or support legal action against researchers who act in good faith and follow this policy ("safe harbour").
- With your permission, we are happy to credit you once the issue is resolved.
Guidelines for researchers
Please:
- Act in good faith and avoid privacy violations, data destruction, and service disruption.
- Only interact with accounts you own or have explicit permission to test.
- Do not access, modify or delete data belonging to others.
- Give us a reasonable time to remediate before any public disclosure.
Out of scope issues
Reports that generally do not qualify include: missing security headers without a demonstrated exploit, rate-limiting concerns without impact, self-XSS, clickjacking on pages without sensitive actions, and theoretical issues without a working proof-of-concept.
Recognition
We do not currently operate a paid bug-bounty program, but we are happy to credit researchers in our security acknowledgements once an issue is resolved. We sincerely thank everyone who helps keep AramGRC and our users safe.
Contact
Questions? Contact contact@aramgrc.com. Or visit our contact page.