Responsible Disclosure
How to tell us about a security problem in Harbor, what you may and may not do while looking, and what we promise in return.
Last updated 19 September 2026
How to report
Email security@harbor.co.nz. Tell us what you found, where, and how to reproduce it. A screenshot or a request and response is enough; you do not need a polished write-up. If you would rather encrypt it, say so and we will send a key.
The machine-readable contact is at /.well-known/security.txt.
What is allowed
- Testing against your own account, or an account we have given you for the purpose
- Reading and reporting what you can see without going further than you need to prove the problem
- Reporting a problem in a third-party service we rely on, so we can pass it on
What is not allowed
- Accessing, copying or changing data about any real student, family, host or school. If you reach it by accident, stop, and tell us what you saw
- Denial of service, load testing or anything that degrades the service for schools
- Social engineering of schools, families, agents or our staff, and physical attempts on premises or devices
- Automated scanning that generates traffic a school would notice
- Publishing the problem before we have fixed it and agreed a date with you
What we commit to
- An acknowledgement within two working days, from a person
- An honest assessment of severity, and a fix date for anything confirmed
- No legal action against good-faith research that follows this page
- Credit on our security page if you would like it, once the fix is live
We do not run a paid bounty programme. We are a small New Zealand company holding records about teenagers a long way from home; we take reports seriously and we say thank you properly.