Introduction
Security is a top priority at Gumugu. We understand that despite our best efforts, vulnerabilities may still exist. We welcome responsible vulnerability reports from the security community as an important part of our security process.
If you believe you have discovered a security vulnerability in the Gumugu platform, we encourage you to report it to us responsibly. We are committed to working with you to understand and address the issue promptly.
This policy applies to all Gumugu products including Gumugu Edu, Gumugu Pesantren, Gumugu Flow, and Gumugu Academy.
Scope
In Scope
Vulnerability reports applicable to the following assets:
app.gumugu.com— Main dashboardapi.gumugu.com— API endpointscdn.gumugu.com— CDN & assetsgumugu.com— Public website
- Parent App (Android & iOS)
- Santri Parent App (Android & iOS)
- School Staff App
Relevant vulnerability types:
Out of Scope
Reports for the following will not be processed and may be considered a violation of this policy.
- Denial of Service attacks (DoS/DDoS)
- Social engineering against Gumugu employees or users
- Physical attacks against Gumugu infrastructure
- Vulnerabilities in third-party services we do not control
- Automated scanning that disrupts service
- Client subdomains/tenants (client-owned *.gumugu.com)
- Issues with no real security impact (e.g. missing low-risk headers)
- Self-XSS requiring unrealistic user interaction
How to Report
Send your vulnerability report via email to:
What to include in your report:
Describe the vulnerability type, location (URL/endpoint), and its potential impact on users or data.
Provide detailed steps required to reproduce the vulnerability. The more detail, the faster we can validate and fix it.
Include screenshots, video, or PoC code. Do not include actual Gumugu user data in your evidence.
Your name or alias and how we can reach you. You may choose to remain anonymous — we will still process your report.
You can submit your report in Indonesian or English. Our team will respond in the same language.
Our Commitments
When you report a vulnerability to us in accordance with this policy, we commit to:
We will confirm receipt of your report within 3 business days of receiving it.
We will provide progress updates every 7 days while the investigation is ongoing.
We will not pursue legal action against researchers who report vulnerabilities in good faith and follow this policy.
With your permission, we will list your name in our Hall of Fame as recognition of your contribution.
We will keep the details of your report confidential and will not share them without your permission.
We target to fix reported vulnerabilities within 90 days. We will notify you once the fix has been deployed.
Rules We Ask Of You
To qualify for safe harbor and receive credit, we ask that you:
Do not publish or share vulnerability details with others before we have had a chance to fix them.
Only test with accounts you own or have explicit permission from the owner. Do not extract, modify, or delete other users' data.
Avoid testing that could damage service availability, including DDoS, flood requests, or aggressive automated scanning.
We ask for at least 90 days to investigate and fix before you publish vulnerability details. If more time is needed, we will discuss it with you.
Testing must comply with applicable law in Indonesia and your country. This policy does not grant permission to break any laws.
Do not attempt to trick or manipulate Gumugu employees, users, or partners to gain access.
Hall of Fame
We proudly acknowledge the security researchers who have helped us make Gumugu safer. Thank you for your contributions.
Be the first!
No reports received yet. Find a vulnerability and report it to us — your name will appear here.
Send the First ReportContact
For questions about this policy or to report a vulnerability, contact our security team:
Our security team is active on business days (Monday–Friday, 09:00–17:00 WIB). We will respond to vulnerability reports as soon as possible, targeting 3 business days for initial acknowledgement.










