Skip to content

Vulnerability disclosure

If you have found something, we want to hear about it. Here is how, and what we commit to in return.

1 min readUpdated 16 August 2026

How do I report a vulnerability?

Email security@vantagepointgrc.com. Reports are acknowledged within one business day. If you would prefer to encrypt, say so in your first message and we will exchange keys.

What should the report include?

The affected host or page, the steps to reproduce, what you observed, and what you believe the impact is. Screenshots or a short proof of concept help; a full exploit chain is not needed. Tell us how you would like to be credited, or if you would rather not be.

What is in scope?

vantagepointgrc.com, vantagepoint.je and vantagepoint.gg and their subdomains, including app.vantagepointgrc.com and api.vantagepointgrc.com (and the legacy app./api.vantagepoint.je hosts that redirect to them). Findings in third-party services we use should go to that provider, but tell us too if you think our configuration is the cause.

What is out of scope?

Denial-of-service testing, social engineering of our staff or customers, physical attacks, automated scanning that degrades the service, and any access to data that is not yours. If you reach customer data by accident, stop, do not retain it, and tell us.

What will Vantage Point do?

Confirm receipt within one business day, triage and tell you what we found, fix confirmed issues on a timescale that matches the risk, and let you know when it is done. We will not take legal action against research that follows this policy in good faith.

Questions: security@vantagepointgrc.com for security,privacy@vantagepointgrc.com for data protection.