Security Disclosure Policy

We take the security of Georithm seriously and welcome responsible reports from security researchers. This page explains the measures we have in place, what is in and out of scope for testing, the rules we ask researchers to follow, and how we handle reports once received.

Version
v1.0
Last updated
29 July 2026

We design Georithm with a number of security measures in place, including:

  • Encryption of data in transit using TLS
  • Encryption of data at rest for stored customer data
  • Secure authentication, including support for modern session and credential handling via our Supabase-backed authentication layer
  • Role-based permissions to limit access to data and features based on account role
  • Rate limiting on sensitive endpoints to reduce abuse and automated attacks
  • Audit logging of significant account and administrative actions

These are measures we maintain and continue to improve; they describe our practices rather than a certified or guaranteed security outcome.

In scope

  • The Georithm web application and its authenticated dashboard
  • Public-facing marketing pages under our primary domain
  • Our first-party APIs used by the Georithm application

Out of scope

  • Third-party providers we integrate with, including Mapbox, Stripe, and Supabase infrastructure (please report issues in those services directly to the relevant provider)
  • Social engineering of our staff, contractors, or customers
  • Physical security attacks against our offices or personnel
  • Volumetric denial-of-service testing
  • Findings produced solely by automated scanners without a demonstrated, exploitable impact

When testing Georithm, please:

  1. Avoid accessing, downloading, or exfiltrating data that does not belong to you
  2. Avoid actions that could violate the privacy of other users
  3. Use your own test accounts wherever possible, rather than real customer accounts
  4. Avoid any activity that degrades service availability or performance for other users
  5. Stop testing and report immediately if you gain unintended access to sensitive data

Please send reports to jerogz@georithm.info. To help us triage quickly, include where possible:

  • A clear description of the vulnerability and its potential impact
  • Step-by-step reproduction instructions
  • Any relevant URLs, request/response data, or screenshots
  • The account or environment used for testing

Please avoid including real customer data in your report; use placeholder or test data wherever practical.

We aim to work through reports as follows, as targets rather than guarantees:

  • Acknowledge receipt of a valid report within a few business days
  • Provide an initial triage assessment indicating whether the report has been accepted for investigation
  • Keep you reasonably informed of progress toward remediation for confirmed issues
  • Coordinate on the timing of any public disclosure once a fix is available

Response and remediation timelines can vary depending on severity and complexity.

We will not pursue legal action against researchers who make a good-faith effort to comply with this policy, report vulnerabilities responsibly, and avoid the prohibited activities described in the rules of engagement above. This safe harbour does not extend to activity that violates the rules of engagement or applicable law.

We do not currently operate a paid bug bounty programme. Where a researcher makes a valuable, responsibly disclosed report, we may, at our discretion, offer public acknowledgement or another form of recognition, unless the researcher prefers to remain anonymous.

For sensitive reports, you may request our current PGP key or another secure communication channel by first contacting jerogz@georithm.info. A PGP key fingerprint, where available, will be published or provided on request: [PGP Key Fingerprint Placeholder].

This document is provided as an original template for Georithm and is maintained by the account owner. It is app-owned editable content and is not legal advice or an independent certification. Replace every bracketed placeholder with your company details and have the final text reviewed by a qualified adviser before relying on it.

Feedback