RecruitMyGame, LLC — Vulnerability Disclosure Policy
Do not open a public GitHub issue for security vulnerabilities. Use the contact address below.
If you discover a security vulnerability in the RecruitMyGame platform, please report it responsibly. We take all reports seriously and will respond promptly.
Send a detailed report to: security@recruitmygame.com
Please include:
| Stage | Timeline |
|---|---|
| Acknowledgment | Within 48 hours |
| Initial assessment | Within 5 business days |
| Critical fix deployed | Within 7 days of confirmation |
| High fix deployed | Within 30 days of confirmation |
| Medium/low fix deployed | Within 90 days of confirmation |
We will keep you informed throughout the process and credit your contribution if you wish.
The following are in scope for security research:
recruitmygame.com and all subdomainsjucoportal.recruitmygame.com and all subdomainsThe following are out of scope:
We will not take legal action against researchers who:
For sensitive reports, you may encrypt your email using our PGP key (available on request via security@recruitmygame.com).
Every pull request and push to main/staging runs the following automated checks. Findings surface in our CI pipeline and block merges on high/critical findings.
| Control | Tool | Cadence |
|---|---|---|
| Static analysis (SAST) | CodeQL | Every PR + push + weekly |
| Dependency CVE audit | npm audit | Every PR + push |
| Secret scanning | TruffleHog | Every PR + push |
| License compliance | license-checker | Every PR + push |
| Dynamic analysis (DAST) | OWASP ZAP | Weekly + on deploy |

Learn about the faces behind Recruit My Game and our mission to help student-athletes achieve their dreams.
Meet Our Team
© 2026 Recruit My Game, Inc. All rights reserved. Built for student-athletes by student-athlete parents who want to help their kid showcase their complete story. Yes, we are a US-based, family run business!