Security
The School for Moral Ambition takes the security of moralambition.org seriously and welcomes reports from security researchers acting in good faith.
How to report
Email security@moralambition.org with details of the issue, steps to reproduce, and any relevant screenshots. We aim to acknowledge within 72 hours.
In scope
- moralambition.org and its subdomains, except those hosted by the third-party platforms listed below
- Email and DNS configuration of the moralambition.org domain
Out of scope
- Third-party platforms we use (community on Circle.so, payment providers, mailing tools) — please report directly to those vendors, who run their own disclosure programs
- Social engineering or physical security
- Denial-of-service testing or volumetric attacks
- Automated scanning that generates significant traffic
Safe harbor
We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations and service disruption
- Only access the minimum data needed to demonstrate the issue
- Give us a reasonable window to fix before public disclosure (90 days)
Acknowledgement
We're a small nonprofit and do not run a paid bug bounty. For significant reports we will, on request, provide a signed letter of acknowledgement on letterhead from The School for Moral Ambition that you can use as a reference.
Related
For privacy or data subject requests, see our Privacy Statement or contact privacy@moralambition.org.