# Security Policy

> Security policy and responsible disclosure guidelines for the Grateful' app.

https://iamgrateful.life/en-GB/security-policy


## Responsible Disclosure

We take the security of Grateful' seriously. If you discover a security vulnerability, we appreciate your help in disclosing it to us responsibly.

### How to Report

Please report security vulnerabilities to: [contact@bobdeyagyesh.in](mailto:contact@bobdeyagyesh.in)

### What to Include

*   Description of the vulnerability
*   Steps to reproduce the issue
*   Potential impact
*   Suggested fix (if any)

### Our Commitment

*   We will acknowledge receipt of your report within 48 hours
*   We will investigate and provide updates on our progress
*   We will work to fix the issue in a timely manner
*   We will credit you in our security acknowledgements (unless you prefer to remain anonymous)

### Scope

This policy applies to the Grateful' web application and any related services. Please do not attempt to access other users' data or perform actions that could affect service availability.

### Out of Scope

*   Social engineering attacks
*   Physical security issues
*   Third-party services not under our direct control
*   Issues that require user interaction to exploit

Last updated: 15 January 2024
