Responsible Disclosure
If you believe you've found a security vulnerability in the AfriGRC platform, we want to hear about it. This page describes what's in scope, how to report a finding, and what you can expect from us in return.
- Last Updated
- August 5, 2026
- Effective Date
- To be confirmed upon legal review
- Version
- 0.1 (Draft)
This page is a working draft of our Responsible Disclosure policy, published for transparency ahead of formal legal review. It does not constitute legal advice, and the Safe Harbor commitment described below should not be treated as a final, legally binding commitment until AfriGRC confirms it has completed that review.
What you can expect from us.
Good-Faith Research Welcomed
We welcome reports from security researchers who test in good faith and report responsibly.
We Investigate Every Report
Every credible report is reviewed by our security team, whether or not it ultimately confirms a vulnerability.
We Won't Pursue Good-Faith Research
AfriGRC does not intend to pursue legal action against research conducted in accordance with this policy — see Safe Harbor below.
We Aim to Communicate Clearly
We aim to keep reporters informed of progress, within the limits described in Response Timeline below.
What's required, monitored, and prohibited while testing.
- Required
Test Against Your Own Account
Use an account you control, or a test/demo environment where one is made available, rather than another organization's live data.
- Required
Report Promptly and Privately
Report a suspected vulnerability to us before disclosing it publicly — see How to Report below.
- Required
Access the Minimum Necessary
Stop and report as soon as you've established that a vulnerability exists — avoid accessing more data than necessary to demonstrate it.
- Monitored
Automated Scanning
Automated scanning is monitored for impact on Platform stability and may be rate-limited or blocked if it affects other users.
- Prohibited
Denial-of-Service Testing
Testing that degrades or disrupts the Services for other users is prohibited under this policy.
- Prohibited
Accessing Other Customers' Data
Attempting to access, modify, or exfiltrate another organization's data is prohibited under this policy.
- Prohibited
Social Engineering
Phishing, social engineering, or physical attacks against AfriGRC personnel or facilities are prohibited under this policy.
Email our security team directly.
Send a report to security@afrigrc.com. To help us triage quickly, include a clear description of the issue, the steps to reproduce it, and its potential impact. Avoid including sensitive data beyond what's needed to demonstrate the vulnerability.
A dedicated report submission form, and a PGP key for encrypted reports, are not yet available — email remains the primary channel in the meantime. See Contact Information below for other ways to reach us.
Enterprise SLA-ready, not yet contractually committed.
This architecture is ready to hold real response-time commitments the moment they're agreed — none are promised here in the meantime.
Acknowledgement
Time to confirm a report has been received.
Future Contractual Content
Triage & Validation
Time to confirm whether a reported issue is a valid vulnerability.
Future Contractual Content
Remediation Updates
How often we aim to update a reporter while a valid issue is being fixed.
Future Contractual Content
Resolution Notification
Notifying the reporter once a valid issue has been resolved.
Future Contractual Content
We don't intend to pursue good-faith research.
AfriGRC does not intend to pursue legal action, or refer a matter to law enforcement, for security research conducted in good faith and in accordance with the Scope described above. If a third party initiates legal action related to research conducted under this policy, AfriGRC will take steps to make clear that the research was authorized under these terms.
This commitment is described here as a working statement of intent, ahead of formal legal review of its exact wording — it should not yet be treated as final, legally binding language.
We intend to say thank you — a formal program isn't live yet.
We value the work of researchers who report responsibly, and intend to acknowledge valid reports — for example, through a future public acknowledgements page — once that mechanism is established.
AfriGRC does not currently operate a paid bug bounty program. If that changes, this section will be updated to describe the program's terms rather than implying one exists today.
See Security & Trust Centre for the broader security architecture a report may relate to.
Every revision, in one place.
- Establishes the page structure: Our Commitment, Scope, How to Report, and the sections that follow.
- Response timeline commitments and the Safe Harbor commitment are placeholder architecture pending legal review.
Questions about this policy.
Found a vulnerability?
Report it directly to our security team, or explore the security architecture behind the platform.