Report a security vulnerability
If you've found a security issue in a Gravwell Inc. system, we want to hear about it. Reports made in good faith under our policy are welcome, and we won't pursue legal action over them.
Where to send it
Email the security team:
This mailbox is monitored by the people who fix security issues. Please don't use general support channels or social media for vulnerability reports, since they aren't private.
If your report contains sensitive details, encrypt it with our PGP key (also on keys.openpgp.org). Fingerprint: 3D6E B802 8BC5 73DE 47A5 9410 8F93 5E93 0667 8D59
What to include
A good report lets us reproduce the issue without coming back to you with questions. Please include:
- The affected URL, hostname, application, or component, and the version if you know it.
- The type of vulnerability and what an attacker could do with it.
- Step-by-step instructions to reproduce it, including any request payloads, scripts, or screenshots.
- Whether you accessed, modified, or kept any data, and if so, what.
- How you'd like to be credited, or that you'd prefer not to be named.
Reports in English are preferred. Short, precise reports are just as valuable as long ones.
What happens next
We'll confirm we received your report within 5 business days and keep you updated as we investigate and fix it. The full timeline, the rules for testing, and our safe-harbor commitment are in the vulnerability disclosure policy. Please read it before you start testing.