How to report an issue
Email [email protected] with the subject “Website security report”. Include the affected URL, a clear description, reproduction steps and any supporting evidence that does not expose another person’s data.
Responsible testing
Please avoid social engineering, privacy violations, data destruction, denial-of-service activity, high-volume automated scanning or any test that could disrupt availability. Do not publish an unresolved vulnerability or access information beyond what is needed to demonstrate the issue.
What to expect
I will aim to acknowledge a credible report within seven days, investigate it in good faith and share a status update when practical. This policy covers the portfolio at garethgrant.com; third-party services and linked projects have their own security scope.
Last updated: 26 September 2026