Қызмет туралы хабарлама

2026 - 2027 оқу жылына өтінімдер қабылдау 2026 жылғы 25 қыркүйекте Лондон уақытымен сағат 17:00-де аяқталады.

Vulnerability disclosure policy

Соңғы жаңарту: 2026 ж. 9 тамыз

Бұл құжат ағылшын тілінде жасалған; ыңғайлылық үшін жасалған кез келген аудармадан ағылшын мәтінінің күші басым. Ағылшын нұсқасын оқу

Applicants trust PolyGrants with identities, documents and payments, so anyone who helps us find a weakness before an attacker does is doing our students a service. This policy says how to report a vulnerability, what we promise in return, and what we ask of you.

What this policy covers

The PolyGrants websites and platform: polygrants.com and its subdomains, the application service behind your account, and the emails PolyGrants sends. If you are unsure whether something is in scope, ask first through the contact below.

Out of scope:

  • services PolyGrants does not operate: the third-party providers named in the Privacy Notice run their own disclosure programmes;
  • denial-of-service testing of any kind;
  • spam, phishing or other social engineering of staff, partners or applicants;
  • physical intrusion into offices or partner offices;
  • findings with no security impact on their own, such as version banners or missing hardening headers presented without an exploit.

How to report

Write to with the word Security in the subject, or use the Contact page. Describe what you found, where, and the steps to reproduce it; include what you needed to prove the issue and nothing more. The machine-readable version of this contact is published at /.well-known/security.txt.

You may report anonymously. If you leave contact details, we can keep you informed and thank you properly.

The rules of good-faith research

We welcome good-faith security research within these rules:

  • make every effort to avoid harming applicants, staff and the Service: no destroying data, no interrupting the Service, no degrading anyone's experience;
  • access, copy or store only the minimum needed to demonstrate the issue, and never another person's personal data where an account of your own would do;
  • stop and report immediately if personal data, credentials or payment information become visible;
  • use a finding for nothing except reporting it to us: no extortion, no sale, no publication before we have had a fair chance to fix it;
  • agree disclosure timing with us; ninety days from your report is our default.

What we promise in return

A human reads every report. We aim to acknowledge within two working days, to tell you what we conclude, and to fix confirmed issues with an urgency that matches their severity.

We will not pursue or support legal action against research done in good faith within the rules above. With your permission, we thank researchers by name. PolyGrants runs no paid bounty programme today; if that ever changes, this page will say so.

What happens to your report

Reports go to the people responsible for the platform's security, are verified, fixed and recorded. Where an issue affected personal data, the commitments of the Privacy Notice apply: if a breach ever puts people at risk, we inform them and the competent authorities as the law requires.

Ownership and review

This policy is owned by the directors of PolyGrants Ltd and reviewed at least once a year. The security.txt file carries an expiry date and is refreshed together with this policy. The date at the top of this page states when it was last updated.

Contact

Security reports: , with Security in the subject. Everything else: the Contact page. PolyGrants Ltd, 128 City Road, London, EC1V 2NX, United Kingdom.

Осы құжат туралы сұрақтарыңыз бар ма? Бізбен байланысу

PolyGrants Ltd · Company No. 16951447 · Біріккен Корольдікте тіркелген