UniWay is a campus map — no user accounts, no payments, no PII stored server-side.
If you find a security issue, report it privately via GitHub Private Vulnerability Reporting rather than opening a public issue.
You can also email uniway.org@gmail.com.
We'll acknowledge receipt within 48 hours and aim to triage within a week.
In-scope: API routes, data handling, authentication bypass (if any). Out-of-scope: Dependency CVEs already tracked by Dependabot, theoretical attacks requiring physical access.
No bug bounty program at this time.