Governance

Security Disclosure

Last updated: August 2026

ZumaGrid holds the operational records of security personnel — where they stood, what they reported, who they are. If you have found a way to read, alter, or destroy data you should not be able to touch, we want to hear from you before anyone else does.

How to report

Email security@zumagrid.app. Please include:

  • What the issue is, and the URL or endpoint where it occurs
  • Steps to reproduce it — a short sequence beats a long description
  • What an attacker could actually do with it
  • How we can reach you, if you want a reply

Reports in any format are read. A rough email that names a real problem is far more useful than a polished one that does not.

What we commit to

  • Acknowledgement within 3 working days — from a person, not an autoresponder
  • An assessment within 10 working days — whether we consider it a vulnerability, and why
  • Progress updates until it is closed, rather than silence after the first reply
  • Credit where you want it, and none where you do not

We do not currently run a paid bug bounty. We would rather say so plainly than imply a reward we have not funded.

Safe harbour

If you act in good faith under this policy, we will not pursue legal action against you, and we will not report you to law enforcement. Good faith means:

  • You test only against your own account and your own data
  • You stop as soon as you have confirmed the issue — you do not enumerate further records to prove scale
  • You do not access, copy, retain, or share other people's data. If you encounter it accidentally, stop and tell us what you saw
  • You do not degrade, disrupt, or deny service to live operations
  • You give us reasonable time to fix the issue before disclosing it publicly

This is a platform used to summon help. Degrading it is not research. Automated scanning against production, denial of service, and social engineering of our staff, customers, or guards all fall outside safe harbour.

In scope

  • zumagrid.app and its subdomains
  • The platform API and its authentication and authorisation paths
  • Anything that lets one organisation read or write another organisation's data — our highest-severity class
  • Privilege escalation between roles, or account takeover

Out of scope

  • Findings from automated scanners with no demonstrated exploit path
  • Missing security headers with no accompanying impact
  • Rate limiting on endpoints that carry no sensitive action
  • Vulnerabilities in third-party services we consume — report those to the service, and tell us so we can respond
  • Social engineering, phishing, and physical attacks on our offices

If people are at immediate risk

If a vulnerability is being actively exploited, or exposes the live location of working guards, mark the subject line URGENT and call +234 706 728 1296. We will treat it as an incident, not a ticket.

For how we handle personal data generally, see our Privacy Policy and Data Processing Agreement. For anything else, use Contact.