Makers Vulnerability Disclosure Policy (VDP)
At Makers Academy, we are committed to preserving the confidentiality, integrity, and availability of all our physical and electronic information assets. We recognise the valuable role that independent security researchers and third parties play in internet security. If you believe you have found a security vulnerability in our software, products, or services, we encourage you to let us know right away.
How to Report a Vulnerability
Please report any actual or suspected security incidents, breaches, or weaknesses immediately to our IT Team and Information Security Manager by emailing: contact@makers.tech
When reporting, please include:
- A detailed description of the vulnerability and its potential impact.
- Step-by-step instructions or proof-of-concept code to reproduce the issue.
- Any relevant IP addresses, URLs, or screenshots.
Rules of Engagement
To protect our users and systems, we require that you follow these guidelines:
- Do not attempt to prove or exploit a suspected weakness. For your own protection, testing or exploiting weaknesses could be interpreted as a potential misuse of our systems.
- Do not access, modify, delete, or store Makers Academy data or the data of our users.
- Do not perform any actions that could impact the availability of our services (e.g., Denial of Service attacks).
- Keep information about any discovered vulnerabilities confidential until we have had adequate time to resolve the issue.
Our Incident Response Commitment
When you submit a report, our Information Security Manager and IT Team will promptly review it to determine its priority and assess the threat.
- We manage and prioritise all reported vulnerabilities based on their business impact and urgency, categorising them from Priority 1 (e.g., severe data breach or loss of service) down to Priority 4 (informational observations).
- Incidents with a high business impact will be escalated to our Tech and Security Council and resolved as a matter of critical priority.
- We will work with you to understand the issue and keep you updated on our progress toward a resolution.
We appreciate your efforts to make Makers Academy more secure.