Security and responsible disclosure

Last updated 29 August 2026 · Version 1.0

If you have found a security problem in GradeLens or on this website, we want to hear about it. This page tells you how to report it and what we will do.

Report a vulnerability

Subject line
Security report
Acknowledgement
Within 5 business days

What to include

Our commitments to you

We do not currently run a paid bug bounty. We are a young company and would rather promise a careful response than a payment we cannot guarantee.

Rules for good-faith research

Please:

Please do not:

In scope

Out of scope

How we protect GradeLens

If something goes wrong

If personal information is ever accessed without authorisation, section 22 of POPIA obliges us to notify the Information Regulator (South Africa) and every affected person as soon as reasonably possible. We will tell you what happened, what was involved, what we have done and what you should do. See our breach commitment.