Vulnerability disclosure policy

Effective October 1, 2026

This policy explains which systems you may test, how to test them safely, how to report what you find, and what you can expect from us in return.

Our commitments at a glance

Acknowledgment
Within 5 business days of your report
Initial assessment
Within 14 business days, including whether we can reproduce it
Status updates
At least every 14 days until the issue is resolved
Public disclosure
Coordinated with you, by default no later than 90 days after your report
Legal action
None, for good-faith research that follows this policy
Automated reports
We discard automated notifications that we assess as not pertinent or applicable to our infrastructure, product, or business

1. Authorization and safe harbor

If you make a good-faith effort to follow this policy during your research, we consider your research authorized. Specifically:

This authorization covers only systems in scope and only conduct that follows the guidelines below. If you're unsure whether something is allowed, ask us at security@gravwell.io before you proceed. We can't authorize testing of systems owned by others, including vendors and service providers we use.

2. Scope

In scope

If you find an issue in a system you believe belongs to us but aren't sure, you may still report it. We'll tell you whether it's ours.

Out of scope

Usually not accepted without a demonstrated impact

These are commonly reported but rarely exploitable on their own. Include a realistic attack scenario if you report one:

3. Guidelines for testing

Under this policy, you agree to:

4. Methods that are not allowed

5. How to report

Send reports to security@gravwell.io. You may report anonymously. If you do, we can't contact you about the fix or credit you.

Please include:

We prefer reports in English. Encrypt sensitive reports with our PGP key (fingerprint 3D6E B802 8BC5 73DE 47A5 9410 8F93 5E93 0667 8D59), also available from keys.openpgp.org.

6. What to expect from us

When you report a vulnerability under this policy, we will:

  1. Acknowledge receipt of your report within 5 business days.
  2. Within 14 business days, tell you whether we could confirm the issue and how we've assessed its severity. We use the Common Vulnerability Scoring System (CVSS) as a guide.
  3. Keep you informed at least every 14 days while we work on a fix, including any delays.
  4. Tell you when the issue is fixed, and give you the chance to verify the fix if you'd like.
  5. Credit you publicly for the finding if you want us to.

We aim to fix confirmed vulnerabilities as quickly as their severity warrants. Critical and high-severity issues take priority. Some fixes, particularly those involving third-party components, may take longer, and we'll explain why when that happens.

7. Public disclosure

We practice coordinated disclosure. We ask that you not share details of a vulnerability publicly until either it has been fixed or 90 days have passed since your report, whichever comes first. If we need more time, we'll explain why and agree on a new date with you. If a vulnerability is being actively exploited, we may agree to an earlier disclosure.

Where appropriate, we'll publish an advisory describing the issue and its fix, and we may request a CVE identifier. We'll coordinate the timing of any advisory with you.

8. Recognition and rewards

With your permission, we'll list you on our acknowledgments page once the issue is resolved. This is a vulnerability disclosure program, not a bug bounty: we don't currently offer monetary rewards, and submitting a report doesn't create any obligation to pay one.

9. Questions and changes

Questions about this policy can be sent to security@gravwell.io. We also welcome suggestions for improving it.

We may update this policy from time to time. The effective date at the top of this page shows when it last changed. Research carried out under an earlier version remains covered by the terms in effect when it was performed.