Skip to content
Book a Demo
RDP.00 / RESPONSIBLE DISCLOSURE

Responsible Disclosure

If you believe you've found a security vulnerability in the AfriGRC platform, we want to hear about it. This page describes what's in scope, how to report a finding, and what you can expect from us in return.

Last Updated
August 5, 2026
Effective Date
To be confirmed upon legal review
Version
0.1 (Draft)

This page is a working draft of our Responsible Disclosure policy, published for transparency ahead of formal legal review. It does not constitute legal advice, and the Safe Harbor commitment described below should not be treated as a final, legally binding commitment until AfriGRC confirms it has completed that review.

RDP.01 / OUR COMMITMENT

What you can expect from us.

TR.01

Good-Faith Research Welcomed

We welcome reports from security researchers who test in good faith and report responsibly.

TR.02

We Investigate Every Report

Every credible report is reviewed by our security team, whether or not it ultimately confirms a vulnerability.

TR.03

We Won't Pursue Good-Faith Research

AfriGRC does not intend to pursue legal action against research conducted in accordance with this policy — see Safe Harbor below.

TR.04

We Aim to Communicate Clearly

We aim to keep reporters informed of progress, within the limits described in Response Timeline below.

RDP.02 / SCOPE

What's required, monitored, and prohibited while testing.

  • Required

    Test Against Your Own Account

    Use an account you control, or a test/demo environment where one is made available, rather than another organization's live data.

  • Required

    Report Promptly and Privately

    Report a suspected vulnerability to us before disclosing it publicly — see How to Report below.

  • Required

    Access the Minimum Necessary

    Stop and report as soon as you've established that a vulnerability exists — avoid accessing more data than necessary to demonstrate it.

  • Monitored

    Automated Scanning

    Automated scanning is monitored for impact on Platform stability and may be rate-limited or blocked if it affects other users.

  • Prohibited

    Denial-of-Service Testing

    Testing that degrades or disrupts the Services for other users is prohibited under this policy.

  • Prohibited

    Accessing Other Customers' Data

    Attempting to access, modify, or exfiltrate another organization's data is prohibited under this policy.

  • Prohibited

    Social Engineering

    Phishing, social engineering, or physical attacks against AfriGRC personnel or facilities are prohibited under this policy.

RDP.03 / HOW TO REPORT

Email our security team directly.

Send a report to security@afrigrc.com. To help us triage quickly, include a clear description of the issue, the steps to reproduce it, and its potential impact. Avoid including sensitive data beyond what's needed to demonstrate the vulnerability.

A dedicated report submission form, and a PGP key for encrypted reports, are not yet available — email remains the primary channel in the meantime. See Contact Information below for other ways to reach us.

RDP.04 / RESPONSE TIMELINE

Enterprise SLA-ready, not yet contractually committed.

This architecture is ready to hold real response-time commitments the moment they're agreed — none are promised here in the meantime.

  • Acknowledgement

    Time to confirm a report has been received.

    Future Contractual Content

  • Triage & Validation

    Time to confirm whether a reported issue is a valid vulnerability.

    Future Contractual Content

  • Remediation Updates

    How often we aim to update a reporter while a valid issue is being fixed.

    Future Contractual Content

  • Resolution Notification

    Notifying the reporter once a valid issue has been resolved.

    Future Contractual Content

RDP.05 / SAFE HARBOR

We don't intend to pursue good-faith research.

AfriGRC does not intend to pursue legal action, or refer a matter to law enforcement, for security research conducted in good faith and in accordance with the Scope described above. If a third party initiates legal action related to research conducted under this policy, AfriGRC will take steps to make clear that the research was authorized under these terms.

This commitment is described here as a working statement of intent, ahead of formal legal review of its exact wording — it should not yet be treated as final, legally binding language.

RDP.06 / RECOGNITION

We intend to say thank you — a formal program isn't live yet.

We value the work of researchers who report responsibly, and intend to acknowledge valid reports — for example, through a future public acknowledgements page — once that mechanism is established.

AfriGRC does not currently operate a paid bug bounty program. If that changes, this section will be updated to describe the program's terms rather than implying one exists today.

See Security & Trust Centre for the broader security architecture a report may relate to.

RDP.07 / CHANGES TO THIS POLICY

Every revision, in one place.

  • Establishes the page structure: Our Commitment, Scope, How to Report, and the sections that follow.
  • Response timeline commitments and the Safe Harbor commitment are placeholder architecture pending legal review.
RDP.08 / CONTACT INFORMATION

Questions about this policy.

Security Team

Report a suspected vulnerability directly to our security team.

Email Security

Legal Team

Questions about the terms of this policy, including Safe Harbor.

Contact Legal

Privacy

Questions about how a report itself, or any data within it, is handled.

Contact Privacy Team
RDP.09 / GET IN TOUCH

Found a vulnerability?

Report it directly to our security team, or explore the security architecture behind the platform.

Responsible Disclosure — AfriGRC