Security Policy — Volunteer Matrix
Scope
This policy applies to volunteermatrix.com, all client subdomains, and associated admin systems.Authorized Use Only
Access to this system is restricted to authorized users for its intended purpose (volunteer scheduling and management). You may not scan, probe, fuzz, brute-force, enumerate, or attempt to bypass authentication or access controls on any part of this system without prior written authorization.This applies equally to human actors and automated agents (bots, scrapers, AI agents, or any autonomous or semi-autonomous tooling) acting on their behalf.
Legal Notice
Unauthorized access or attempted access to this system may violate the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and comparable state and international laws.Violations may be referred to law enforcement.
Monitoring
Access to this system is logged, including IP address, request headers, and timestamps. Logs are reviewed and retained for security purposes.Reporting a Vulnerability
If you believe you've found a security issue, we want to know. Email security@volunteermatrix.com with details. Do not test findings beyond what's necessary to demonstrate the issue, and do not access, modify, or exfiltrate client data.Good-faith reports made without violating the restrictions above will not result in legal action from us. We will acknowledge reports within [7 business days].
Last updated: September 7, 2026