Security

What is true, what is not yet, and how to tell us.

Written for the person at a district or a county who has to sign off on a website before staff may use it.

Reporting a vulnerability

security@seedstand.org. Reports are read by the people who write the software, not by a ticket system. You will hear back from a person.

We will not pursue legal action against anyone who reports a genuine vulnerability in good faith and gives us reasonable time to fix it.

Please do not access, modify, or exfiltrate other people's data while testing; a proof of concept against your own district account is enough.

What is true today

What is not yet true

Where the data is

The application runs on Vercel and the database is Neon Postgres, both in the United States. Transactional email goes through Resend; card payments, where a district turns them on, go directly to Stripe and card numbers never reach our servers. The privacy page lists these processors and what each receives. Privacy · Status