Vulnerability Disclosure Policy

At FULL POWER Ministries, we take the security of our systems and the privacy of our users seriously. We appreciate the work of security researchers and the broader community in helping us maintain a secure ecosystem.

If you believe you have found a security vulnerability in our website or services, we encourage you to let us know right away.

1. How to Report a Vulnerability

Please submit all security vulnerability reports directly to our team:

  • Email: security@wearefullpower.org

  • What to include:

    • A detailed description of the vulnerability.

    • The specific URL, endpoint, or system affected.

    • Step-by-step instructions (or a proof-of-concept script) to reproduce the issue.

    • Your contact information (if you wish to receive updates).

2. Our Commitments to You

If you follow this policy to report a vulnerability, we commit to the following:

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days.

  • Investigation: We will investigate the issue promptly and keep you updated on our progress toward a fix.

  • Safe Harbor: We will not take legal action against you or request law enforcement investigations, provided you adhere to the guidelines below.

3. Guidelines and Restrictions

To protect our users and infrastructure, we ask that you adhere to the following rules during your research:

Do:

  • Play by the rules. Avoid violating privacy, destroying data, or interrupting our services.

  • Give us a reasonable amount of time to resolve the issue before making any information public.

Do Not:

  • No DDoS: Do not perform Denial of Service (DoS) or Distributed Denial of Service (DDoS) attacks.

  • No Social Engineering: Do not target our staff, users, or contractors with phishing, social engineering, or physical security attacks.

  • No Data Exfiltration: If you gain access to sensitive data (including personal information or credentials), do not download, modify, or retain it. View only what is necessary to prove the vulnerability.

  • No Automated Spam: Do not use automated scanners that generate high volumes of traffic and disrupt our services.

4. Public Recognition

We appreciate your help in keeping us safe. Unless you request anonymity, we are happy to publicly acknowledge your contribution to our security once the vulnerability has been fully resolved and patched.

Thank you for helping keep FULL POWER Ministries secure.