Skip to main content

Join the virtual 2026 My Green Lab Global Summit, September 29–30. Meeting the moment: connect with sustainability leaders across the globe shaping the future of sustainable science. Register now to secure your spot.

Register to Join
My Green Planet
Security

Last Updated: 07/08/2026

 

Summary

Impact Laboratories and My Green Lab are committed to protecting the security and privacy of our systems and users.

This policy provides a channel for responsible reporting of legitimate security vulnerabilities affecting our in-scope systems.

This is not a bug bounty program. We do not provide compensation, rewards, certificates, public recognition, or other consideration for unsolicited vulnerability reports.

Scope

This policy applies only to internet-facing systems directly owned and operated by Impact Laboratories / My Green Lab, including designated production web applications and APIs.

Out of scope:

  • Social engineering
  • Phishing
  • Physical security testing
  • Denial of service or load testing
  • Spam
  • Credential stuffing
  • Automated high-volume scanning
  • Brute force testing
  • Attacks against third-party systems or vendors
  • Testing that accesses, modifies, or destroys data belonging to others

Submission Requirements

Reports should include:

  • Affected URL, application, or system
  • Clear reproduction steps
  • Description of demonstrated security impact
  • Sufficient detail for validation

Reports may be closed without action if they consist solely of:

  • Automated scanner output
  • Theoretical findings without demonstrated exploitability
  • Informational or low-risk observations
  • Duplicate submissions
  • Best-practice recommendations

Examples may include:

  • Missing security headers
  • Cookie configuration observations without material exploitability
  • SPF / DKIM / DMARC recommendations
  • Version disclosures
  • TLS configuration preferences
  • Clickjacking claims without demonstrated impact

Submit reports to:
security@mygreenlab.org

Authorized Conduct/Safe Harbor

If you comply with this policy, we will not pursue legal action solely for good-faith security research within the authorized scope of this policy.

Authorized activity does not include:

  • Service disruption
  • Automated scanning that creates operational burden
  • Accessing data beyond your own authorization
  • Persistence, privilege escalation, or lateral movement
  • Attempts to exfiltrate data
  • Attacks against personnel, vendors, or customers

Review Process

We review submissions at our discretion based on severity, impact, reproducibility, and operational relevance.

Submission does not create any obligation to respond, remediate, provide status updates, or correspond further.

Coordinated Disclosure

We request coordinated disclosure and ask that researchers refrain from public disclosure until we have had a reasonable opportunity to assess reported issues.

My Green Lab

Join our newsletter mailing list

Stay connected to the sustainability community by receiving our monthly newsletter that provides news, events, updates on programs and initiatives, partner success stories, certification tips, and more!

Sign up
Follow us

© 2026 My Green Lab