Security
Vulnerability Disclosure Policy
Fundly welcomes reports from security researchers and from district IT and procurement teams evaluating the platform. This page describes what is in scope, how to report, and what to expect after you do. A machine-readable copy of this information is published at /.well-known/security.txt.
Effective: June 11, 2026. Reviewed at least annually and after any material change to our incident-response process.
Scope
Only the systems Fundly operates are in scope. Each organization on Fundly is responsible for its own infrastructure, devices, and accounts elsewhere.
| Status | System / category | Notes |
|---|---|---|
| In scope | Fundly web application (app, dashboard, public pages) | All authenticated and unauthenticated functionality served from our production host. |
| In scope | Fundly public API | API endpoints used by the web app and by organization integrations (OneRoster, QuickBooks, Mailchimp, embeddable widget). |
| Out of scope | On-prem org infrastructure | Laptops, networks, and accounts belonging to the organization’s own staff, students, and donors. These are the org’s IT, not Fundly’s. |
| Out of scope | Third-party processors | Stripe, print-on-demand providers, email providers, and similar vendors should be reported to those vendors directly. |
| Out of scope | Informational findings | Missing security headers with no demonstrated impact, open redirect on a non-authenticated marketing page, rate limiting gaps that cannot be reached in practice, and similar low-severity observations. |
How to report
Send a clear, written report to [email protected]. A well-formed report includes:
- The affected system and URL. One URL or endpoint per report unless they share a root cause.
- A concise description of the issue. What it is, who is affected, and the security impact.
- Reproduction steps. A minimal, end-to-end set of steps a Fundly engineer can follow to reproduce.
- Your assessment of severity. CVSS 3.1 score is helpful but optional.
- Your contact details and a preferred disclosure timeline.
We accept reports in English. We do not currently require encryption, but if your finding is sensitive and you would like to share it encrypted, request a PGP key in your initial email and we will reply with one.
Our commitments
- Acknowledgment within 3 business days of receiving your report. We will confirm we have read it and assign an initial severity.
- A status update at least every 10 business days until the issue is resolved or declined with a written reason.
- 90-day coordinated-disclosure target. We aim to publish a fix (or a documented mitigation) within 90 days of acknowledgment, and to coordinate a public disclosure date with you. We will not publish details of an unremediated issue without your agreement.
- Credit on request. With your permission, we will list you in the acknowledgments section of /security after disclosure.
Safe harbor
When you conduct security research and submit a report in good faith through the channel above, Fundly will not pursue civil or criminal action against you, and will not refer the matter to law enforcement, provided your research:
- Stays within the scope listed above.
- Avoids privacy violations, including the deliberate exfiltration or retention of donor or student personal data.
- Does not use social engineering against Fundly staff, organization admins, advisors, or supporters.
- Does not generate denial-of-service conditions, large-scale spam, or destructive automated load against production systems.
- Gives us a reasonable opportunity to fix the issue before any public disclosure.
We consider research conducted under this policy to be authorized access for the purposes of the Computer Fraud and Abuse Act and equivalent laws. This paragraph is a commitment, not a legal advice; if you are uncertain, send us your plan first and we will respond.
What to avoid
During testing please do not:
- Read, modify, or retain data belonging to a real organization, advisor, student, or donor. Use a test organization of your own.
- Run automated scanners that generate large volumes of traffic or that create audit-log noise on a real organization’s account.
- Attempt phishing, password spraying, or other social-engineering attacks against Fundly staff or users.
- Test physical security, third-party vendors, or any of the out-of-scope items in the table above.
See also
- Security & compliance overview — published commitments, operational practices, acknowledgments.
- /.well-known/security.txt — machine-readable disclosure record (RFC 9116).
- Privacy Policy — the authoritative document for what data Fundly collects and how long it is retained.
This page is also reachable at the canonical URL https://fundly.app/security/disclosure (declared in security.txt as Policy:) and at https://fundly.app/security (Acknowledgments:).