Why sign up first?
So we can tell you yes, you're cleared to look, and so reports come from people we know. It keeps everyone out of trouble.
A private sign-up program for finding security problems before anyone else does. Whatever you report stays between you and our team. Sign up to take part, or if you already spotted something, send it straight to us.
Want to help look for security issues? Add your name and we'll reach out with how to take part. Nothing about scope is posted here; we share that one to one once you're in.
Send your name, say whether you're a Vista Grande student, staff, or an outside researcher, and promise to keep anything you find quiet until it's fixed. Give us a personal email to set the account up on, not a school one.
So we can tell you yes, you're cleared to look, and so reports come from people we know. It keeps everyone out of trouble.
Your name, a personal email, and a quick promise to keep things private.
We create your access, write down exactly what you may test, and email you.
Your own console: your scope, the rules, any tasks, and a private line to us.
Not a school one. Bug bounty access is its own account, kept separate on purpose, so when it ends nothing else about you ends with it.
Applies to students and staff tooAccess is time-boxed, never longer than 62 days at a time. We'll email you a week and again three days before it ends.
After that you can't sign in until we renew itYou'll set one up before you can get in: an authenticator app, a passkey, or a security key. There's no way around it.
A passkey or security key is strongestYou don't need to sign up first. If you came across a security problem, even by accident, tell us privately through any of these and we'll take it from there.
Open a private security advisory on the repo. Best if you have a GitHub account and repro steps to share.
Open GitHub's Security tab →Private · coordinated disclosureSign in and file it through the report form, tagged as a security concern. Attach a proof-of-concept or screenshots, up to 25 MB.
Open the report form →Signed-in · attach files · lands in our consoleNo account needed. Email what you saw and where, privately. It reaches the same team as the other two.
Email developer@dev.vgspartans.org →Keep it out of public viewKeep it short, we'll follow up with questions.
A person reads it, and we try to reply within a week. We fix the issue and put your name on it if you want the credit. We can't offer cash, but the credit is yours.