Skip to policy content
Signup Crew — Plan more. Do more. Together.
PrivacyTermsAccessibilitySecurity

Signup Crew policy information

Vulnerability Disclosure Policy

Draft boundaries for reporting potential Signup Crew vulnerabilities.

Draft / Pending Legal ReviewNot yet effective

This draft is provided for review and is not a final or effective published policy.

Version
Draft 0.1
Effective date
Not yet effective
Last updated
September 6, 2026
No testing authorization

Viewing this draft does not authorize testing of Signup Crew, Development, Production, or any third-party system.

This draft is not an authorization to test Signup Crew, Development, Production, or any third-party system. A final policy must identify the exact authorized scope and be approved and published before its safe-harbor terms can apply.

Purpose

Just Walking Ventures, LLC, doing business as Signup Crew, welcomes responsible, good-faith reports that help protect customers, Volunteers, RSVP participants, users, the Service, and third-party providers. This proposed policy describes the boundaries a final Signup Crew vulnerability disclosure program should use.

Reporting a potential vulnerability

Until another channel is approved, send a report to support@signupcrew.com with the subject Security report.

When it is safe to do so, include:

  • the affected Signup Crew URL or workflow;
  • a description of the potential vulnerability;
  • the minimum reproducible steps;
  • the likely or observed impact;
  • screenshots or other evidence that do not unnecessarily expose another person's information; and
  • contact information if you would like follow-up.

Do not include passwords, authentication tokens, full payment-card information, provider credentials, or personal information that is not necessary to explain the report.

No acknowledgement, response, remediation, or payment deadline is promised by this draft.

Expected good-faith boundaries

Any final testing authorization will be limited to specifically identified Signup Crew-owned web application surfaces. Development is not automatically an open researcher-testing environment, and neither Development nor Production is open to unrestricted testing.

Expected good-faith boundaries include:

  • use only accounts and data you own or have express permission to use where authentication is required;
  • perform only the minimum testing necessary to demonstrate a potential vulnerability;
  • do not access, change, download, retain, or share information belonging to another customer, Volunteer, RSVP participant, or user;
  • if you unexpectedly encounter another person's information, stop testing, avoid further access or retention, and report the issue promptly;
  • avoid destructive testing or any action that could alter or delete data;
  • avoid denial-of-service, load, stress, or availability testing;
  • avoid spam, bulk communications, or mass account creation;
  • avoid social engineering, phishing, physical attacks, or impersonation of employees, customers, participants, or providers;
  • do not deploy malware or attempt to establish persistence;
  • do not attempt to obtain secrets, provider credentials, or authentication tokens; and
  • do not treat this reporting policy as authority to exceed its stated scope.

Third-party systems are out of scope

This proposed policy does not authorize testing or attacking infrastructure, accounts, products, or services operated by Supabase, Stripe, Resend, Vercel, Google, or another third party. A provider's own vulnerability disclosure or security policy governs testing of its systems.

If a potential issue appears to involve a Signup Crew integration with a provider, report the Signup Crew impact without testing the provider's infrastructure or attempting to obtain provider secrets.

Disclosure coordination

We ask researchers to give Signup Crew a reasonable opportunity to investigate and address a report before public disclosure. Any final coordination process should account for the nature of the issue, risks to users, and applicable law.

This draft does not establish a fixed embargo, guaranteed acknowledgement, response or remediation timeline, bug bounty, reward, fee, or payment.

Draft safe harbor

Subject to applicable law, Signup Crew does not intend to pursue legal action against a researcher for good-faith security research that is conducted in accordance with the final, approved, and published Vulnerability Disclosure Policy and stays within its authorized scope.

This proposed safe harbor is conditional. It is not a blanket authorization for unrestricted testing and does not apply to activity outside the policy, including unauthorized access to another person's information, destructive or disruptive testing, attacks on third-party systems, extortion, or violations of applicable law.

Questions or assistance? Email Signup Crew Support.

Signup Crew homeSupport