# RFC 9116 security contact for The Global Conservatory # Operating brand of Kalinklo Limited (Hong Kong SAR) # Last updated: 2026-05-05 Contact: mailto:security@theglobalconservatory.com Contact: https://theglobalconservatory.com/pages/contact Expires: 2027-05-05T00:00:00.000Z Preferred-Languages: en Canonical: https://theglobalconservatory.com/pages/security Policy: https://theglobalconservatory.com/pages/acceptable-use-policy Acknowledgments: https://theglobalconservatory.com/pages/security#acknowledgments
Reporting Security Vulnerabilities
If you have discovered a security vulnerability affecting theglobalconservatory.com, the customer portal at portal.theglobalconservatory.com, the faculty application portal at teach.theglobalconservatory.com, or the admissions portal at apply.theglobalconservatory.com, please report it responsibly to:
security@theglobalconservatory.com
What to include in your report
- A description of the vulnerability and its potential impact
- Steps to reproduce, including any URLs, payloads, or test accounts used
- Whether you have shared this with anyone else (we ask you not to)
- Your name and how you'd like to be acknowledged (or "anonymous")
Our commitment
- Acknowledge your report within 5 business days
- Assess the report and provide an initial response within 10 business days
- Coordinate on disclosure timeline that gives us reasonable time to remediate (typically 90 days)
- Acknowledge you publicly on this page (or anonymously, your choice) once the issue is resolved
- Not pursue legal action against good-faith security researchers who follow this policy
Out of scope
- Denial of service attacks, brute-force attacks, social engineering
- Issues in third-party services (Shopify itself, payment providers, Zoom, etc.) — please report to those vendors directly
- Vulnerabilities in software whose patches we cannot deploy (e.g., end-user browser bugs)
- Reports from automated scanners without proof of impact
Acknowledgments
We thank the following security researchers for responsibly disclosing vulnerabilities. (List will be populated as reports come in.)
For non-security legal inquiries, see our Contact Information. For acceptable use, see our Acceptable Use Policy.