Home › Security

Security Policy

Feed America (501(c)(3), EIN 92-1761881) takes the security of our public food-assistance directory seriously. We welcome vulnerability reports from security researchers and commit to coordinated disclosure within reasonable timelines.

How to report a vulnerability

Email security@feedam.org with:

If you prefer encrypted communication, request our PGP key in your initial email and we'll respond with it.

Response expectations

Scope

The following are in scope:

The following are out of scope:

Vulnerability classes we're particularly interested in

Out-of-scope reports

We will not act on the following without supporting evidence of real-world impact:

Safe-harbor commitment

If you make a good-faith effort to comply with this policy, we will not pursue civil or criminal action against you. Specifically, we promise:

To stay in safe harbor:

Acknowledgments

Security researchers who have reported vulnerabilities responsibly will be listed here (with permission). The list is currently empty — be the first.

Machine-readable

RFC 9116 security.txt: /.well-known/security.txt

Bug bounty

We're a 501(c)(3) operating on platform-infrastructure costs only — we do not currently offer monetary rewards. We do offer:

Questions about this policy

For general security or privacy questions: security@feedam.org. For privacy questions specifically: see our privacy policy.

This policy is published per RFC 9116. Last reviewed: 2026-04-29 · Transparency · Privacy · Disclosures