Responsible Disclosure
Last updated: August 2026
If you've found a security issue on grandcapitalcleaning.com, we want to know about it. This page explains how to report it to us safely, and what to expect.
Scope
This policy covers the grandcapitalcleaning.com website and its estimate-request form and backend. It does not cover third-party services we merely use (for example, Cloudflare's own platform, or Google Fonts). Please report issues in those directly to their own security teams.
How to report
Email hello@grandcapitalcleaning.com with the subject line "Security Report" and include:
- A description of the issue and its potential impact.
- Steps to reproduce it (URLs, request details, screenshots, whatever helps us confirm it quickly).
- Your contact information, if you'd like to be credited or kept updated.
Our commitment
We won't pursue legal action against anyone who makes a good-faith effort to report a vulnerability in line with this policy. We'll acknowledge your report, investigate promptly, and let you know once it's resolved.
Ground rules
Please:
- Give us a reasonable amount of time to fix an issue before disclosing it publicly.
- Avoid accessing, modifying, or deleting data that isn't yours.
- Don't run automated scanners that could degrade the Site for real visitors, and don't attempt denial-of-service testing.
- Don't use social engineering against our staff or customers.
- Only test against the scope described above.
Found something?
hello@grandcapitalcleaning.com (subject line: "Security Report")
