Gapwise handles student schedule and account-adjacent information, so security reports should be handled privately and with enough detail to reproduce the issue safely.
Please email security@gapwise.ca.
Do not open a public GitHub issue for vulnerabilities involving authentication, authorization, encryption, private student state, secrets, infrastructure access, data exposure or abuse paths.
A useful report includes:
- the affected Gapwise repository or public surface;
- a concise description of the issue and its impact;
- reproducible steps or a minimal proof of concept;
- affected URLs, endpoints, versions or commits when known;
- any mitigations you have already identified.
Please avoid accessing, modifying or retaining data that does not belong to you. Do not degrade production availability while testing.
This policy applies across the public Gapwise ecosystem, including:
gapwiseandroidiosaidatadocsstatus
Repository-specific security guidance takes precedence where present.
Non-sensitive correctness, reliability, accessibility and ordinary bug reports can be filed publicly in the repository that owns the behavior.
Security: security@gapwise.ca
Support: support@gapwise.ca
Status: https://status.gapwise.ca
Gapwise is an independent student project and is not affiliated with, endorsed by, or an official service of the University of Toronto.