Report a security vulnerability

If you've found a security issue in a Gravwell Inc. system, we want to hear about it. Reports made in good faith under our policy are welcome, and we won't pursue legal action over them.

Where to send it

Email the security team:

security@gravwell.io

This mailbox is monitored by the people who fix security issues. Please don't use general support channels or social media for vulnerability reports, since they aren't private.

If your report contains sensitive details, encrypt it with our PGP key (also on keys.openpgp.org). Fingerprint: 3D6E B802 8BC5 73DE 47A5 9410 8F93 5E93 0667 8D59

What to include

A good report lets us reproduce the issue without coming back to you with questions. Please include:

Reports in English are preferred. Short, precise reports are just as valuable as long ones.

What happens next

We'll confirm we received your report within 5 business days and keep you updated as we investigate and fix it. The full timeline, the rules for testing, and our safe-harbor commitment are in the vulnerability disclosure policy. Please read it before you start testing.