Security Disclosure Policy

Last updated 3 min read
Report issue

Security Disclosure Policy#

We take security seriously. This page tells you how to report a vulnerability and what to expect from us.

What's in scope#

  • Anything at *.gritiva.com (panel, api, docs, monitor)
  • The gritiva-agent binary and the gmeshd daemon
  • The gritiva-docs-backend and gritiva-docs-frontend
  • Cloudflared / nginx-in-scope configurations we generate

What's NOT in scope#

  • Customer scopes / customer applications (those are operated by customers; report to them)
  • Third-party services we use (Cloudflare, Hetzner, Stripe — report to them directly)
  • Volumetric DoS — we have Cloudflare; please don't actually DoS us to demonstrate
  • Social engineering of our staff
  • Physical security of our offices (we don't have any)

How to report#

Email [email protected].

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce (with screenshots / curls if applicable)
  • The earliest version affected (if known)
  • Your assessment of impact / CVSS estimate
  • Whether you'd like credit (and the name to use)

PGP key is at https://gritiva.com/.well-known/security-pgp-key.asc — use it for high-severity reports.

Our commitment to you#

  • Acknowledgment within 24 hours (business days)
  • Initial triage within 72 hours — we'll tell you if it's confirmed, severity, and rough timeline
  • Status updates every 7 days until resolution
  • Credit in the security advisory if you want it
  • No legal action if you stick to this policy and act in good faith (Safe Harbor below)

Safe Harbor#

We will not pursue legal action against researchers who:

  1. Make a good-faith effort to comply with this policy
  2. Don't access, modify, or destroy data beyond what's needed to demonstrate the issue
  3. Don't violate the privacy of users or staff
  4. Don't perform attacks that disrupt service availability (no DoS, no flooding, no spam)
  5. Give us reasonable time to fix before public disclosure

Specifically, you're authorized to:

  • Probe public-facing endpoints
  • Test the agent binary locally
  • Review source code (it's public)
  • Use the free plan for testing (please don't sign up under multiple identities to abuse limits)

Bounty#

We don't currently run a paid bug bounty program — we're bootstrapped and small. We do offer:

  • Public credit in our security advisories
  • GritivaCore Pro for life for confirmed High/Critical findings (one account, you keep it)
  • Swag when we have it (T-shirt, sticker pack)
  • A genuine thank-you and reference if you'd like one for your portfolio

Once we're cash-flow positive (target: late 2026), we'll launch a formal bounty.

Disclosure timeline#

We aim for 90 days from confirmed report to public disclosure. Most fixes ship in 14-30 days; the longer window allows for coordinated disclosure with downstream users when relevant.

If 90 days passes without a fix and there's no compelling reason to extend (e.g. coordinated CVE), the reporter is free to publish.

Past advisories#

DateTitleSeverityCredit
(none yet)(none yet)

We've had no public security advisories to date. We'll publish here when we do.

Contact#