Security · Responsible Disclosure

Responsible Disclosure Policy

Gumugu is committed to protecting the data of schools, pesantren, and organizations that trust us. We deeply value security researchers who help us stay secure.

Acknowledged within 3 business days
90-day fix window
Safe harbor for good-faith researchers

Introduction

Security is a top priority at Gumugu. We understand that despite our best efforts, vulnerabilities may still exist. We welcome responsible vulnerability reports from the security community as an important part of our security process.

If you believe you have discovered a security vulnerability in the Gumugu platform, we encourage you to report it to us responsibly. We are committed to working with you to understand and address the issue promptly.

This policy applies to all Gumugu products including Gumugu Edu, Gumugu Pesantren, Gumugu Flow, and Gumugu Academy.

Scope

In Scope

Vulnerability reports applicable to the following assets:

Core Platform
  • app.gumugu.com — Main dashboard
  • api.gumugu.com — API endpoints
  • cdn.gumugu.com — CDN & assets
  • gumugu.com — Public website
Mobile Apps
  • Parent App (Android & iOS)
  • Santri Parent App (Android & iOS)
  • School Staff App

Relevant vulnerability types:

SQL Injection
Cross-Site Scripting (XSS)
Cross-Site Request Forgery (CSRF)
Server-Side Request Forgery (SSRF)
Broken Authentication
Insecure Direct Object Reference (IDOR)
Remote Code Execution (RCE)
Privilege Escalation
Sensitive Data Exposure
Business Logic Vulnerabilities

Out of Scope

Reports for the following will not be processed and may be considered a violation of this policy.

  • Denial of Service attacks (DoS/DDoS)
  • Social engineering against Gumugu employees or users
  • Physical attacks against Gumugu infrastructure
  • Vulnerabilities in third-party services we do not control
  • Automated scanning that disrupts service
  • Client subdomains/tenants (client-owned *.gumugu.com)
  • Issues with no real security impact (e.g. missing low-risk headers)
  • Self-XSS requiring unrealistic user interaction

How to Report

Send your vulnerability report via email to:

What to include in your report:

1
Vulnerability description

Describe the vulnerability type, location (URL/endpoint), and its potential impact on users or data.

2
Steps to reproduce

Provide detailed steps required to reproduce the vulnerability. The more detail, the faster we can validate and fix it.

3
Proof of Concept

Include screenshots, video, or PoC code. Do not include actual Gumugu user data in your evidence.

4
Contact information

Your name or alias and how we can reach you. You may choose to remain anonymous — we will still process your report.

You can submit your report in Indonesian or English. Our team will respond in the same language.

Our Commitments

When you report a vulnerability to us in accordance with this policy, we commit to:

Acknowledge within 3 business days

We will confirm receipt of your report within 3 business days of receiving it.

Updates every 7 days

We will provide progress updates every 7 days while the investigation is ongoing.

Safe harbor & legal protection

We will not pursue legal action against researchers who report vulnerabilities in good faith and follow this policy.

Credit & recognition

With your permission, we will list your name in our Hall of Fame as recognition of your contribution.

Report confidentiality

We will keep the details of your report confidential and will not share them without your permission.

90-day fix target

We target to fix reported vulnerabilities within 90 days. We will notify you once the fix has been deployed.

Rules We Ask Of You

To qualify for safe harbor and receive credit, we ask that you:

Report to us first

Do not publish or share vulnerability details with others before we have had a chance to fix them.

Do not access other users' data

Only test with accounts you own or have explicit permission from the owner. Do not extract, modify, or delete other users' data.

Do not disrupt services

Avoid testing that could damage service availability, including DDoS, flood requests, or aggressive automated scanning.

Allow 90 days before public disclosure

We ask for at least 90 days to investigate and fix before you publish vulnerability details. If more time is needed, we will discuss it with you.

Act within the law

Testing must comply with applicable law in Indonesia and your country. This policy does not grant permission to break any laws.

Do not engage in social engineering

Do not attempt to trick or manipulate Gumugu employees, users, or partners to gain access.

Hall of Fame

We proudly acknowledge the security researchers who have helped us make Gumugu safer. Thank you for your contributions.

Be the first!

No reports received yet. Find a vulnerability and report it to us — your name will appear here.

Send the First Report

Contact

For questions about this policy or to report a vulnerability, contact our security team:

Our security team is active on business days (Monday–Friday, 09:00–17:00 WIB). We will respond to vulnerability reports as soon as possible, targeting 3 business days for initial acknowledgement.

This policy was last updated: July 2026

Found something? Let us know.

Your report helps us keep thousands of schools and pesantren safe — all of which trust Gumugu with their data.

Send a Security Report
Trusted by

Not sure which modules are right for you?

Our team will help you pick the modules that best fit your needs and budget — no pressure, no commitment.

Free consultation No credit card required Response within 1 business day
Gumugu Team
Online now

Hi! I'm ready to help you find the right Gumugu modules for your organization. Where would you like to start?

Now
Start a Conversation