Tell us the affected address, what you found, and the steps to reproduce it. A screenshot or a short recording helps. Please do not post it publicly before we have had a chance to fix it.
What we commit to
We acknowledge your report within three working days.
We tell you our assessment, and if we disagree that it is a vulnerability we explain why rather than going quiet.
We fix confirmed issues as quickly as the severity warrants, and we tell you when it is done.
We will not pursue legal action against anyone who reports a problem in good faith, follows this page, and does not access, alter or destroy other people's data.
We credit you if you would like to be credited.
We do not run a paid bug bounty. We are a small company and we would rather be honest about that than imply a reward we do not offer.
Please do not
Run denial of service or volumetric load tests against our sites.
Access, modify or delete data belonging to anyone else. If you can prove access, stop there and tell us.
Use social engineering, phishing or physical intrusion against our staff or suppliers.
Automate scanning at a volume that degrades the service for readers.
How this site is built
GRCcareers.ai is deliberately simple, because the smallest attack surface is the one that is not there.
Static pages. There is no application server, no database and no content management system behind this site. Pages are files.
No accounts. There is no login, so there are no credentials here to steal.
No third-party scripts. Nothing loads from another domain, which removes an entire class of supply chain risk.
HTTPS everywhere, served through Cloudflare, which also absorbs attack traffic.
Systems that do hold personal data, such as job alerts and employer accounts, live on AI-Governance-Jobs.com. Report issues with those to the same address.
If you are a reader
We will never email you asking for a password, and we will never ask a job seeker for payment or bank details. If you receive something claiming to be from us that does either, it is not from us. See avoiding scams, and please forward it to us so we can warn others.