Skip to content

Security: GapwiseHQ/ios

Security

SECURITY.md

Security policy

Gapwise handles student schedule and account-adjacent information, so security reports should be handled privately and with enough detail to reproduce the issue safely.

Reporting a vulnerability

Please email security@gapwise.ca.

Do not open a public GitHub issue for vulnerabilities involving authentication, authorization, encryption, private student state, secrets, infrastructure access, data exposure or abuse paths.

A useful report includes:

  • the affected Gapwise repository or public surface;
  • a concise description of the issue and its impact;
  • reproducible steps or a minimal proof of concept;
  • affected URLs, endpoints, versions or commits when known;
  • any mitigations you have already identified.

Please avoid accessing, modifying or retaining data that does not belong to you. Do not degrade production availability while testing.

Scope

This policy applies across the public Gapwise ecosystem, including:

  • gapwise
  • android
  • ios
  • ai
  • data
  • docs
  • status

Repository-specific security guidance takes precedence where present.

Public issues

Non-sensitive correctness, reliability, accessibility and ordinary bug reports can be filed publicly in the repository that owns the behavior.

Contact

Security: security@gapwise.ca
Support: support@gapwise.ca
Status: https://status.gapwise.ca

Gapwise is an independent student project and is not affiliated with, endorsed by, or an official service of the University of Toronto.

There aren't any published security advisories