Security Disclosure Policy
Security Disclosure Policy#
We take security seriously. This page tells you how to report a vulnerability and what to expect from us.
What's in scope#
- Anything at
*.gritiva.com(panel, api, docs, monitor) - The
gritiva-agentbinary and thegmeshddaemon - The
gritiva-docs-backendandgritiva-docs-frontend - Cloudflared / nginx-in-scope configurations we generate
What's NOT in scope#
- Customer scopes / customer applications (those are operated by customers; report to them)
- Third-party services we use (Cloudflare, Hetzner, Stripe — report to them directly)
- Volumetric DoS — we have Cloudflare; please don't actually DoS us to demonstrate
- Social engineering of our staff
- Physical security of our offices (we don't have any)
How to report#
Email [email protected].
Please include:
- A clear description of the vulnerability
- Steps to reproduce (with screenshots / curls if applicable)
- The earliest version affected (if known)
- Your assessment of impact / CVSS estimate
- Whether you'd like credit (and the name to use)
PGP key is at https://gritiva.com/.well-known/security-pgp-key.asc — use it for high-severity reports.
Our commitment to you#
- Acknowledgment within 24 hours (business days)
- Initial triage within 72 hours — we'll tell you if it's confirmed, severity, and rough timeline
- Status updates every 7 days until resolution
- Credit in the security advisory if you want it
- No legal action if you stick to this policy and act in good faith (Safe Harbor below)
Safe Harbor#
We will not pursue legal action against researchers who:
- Make a good-faith effort to comply with this policy
- Don't access, modify, or destroy data beyond what's needed to demonstrate the issue
- Don't violate the privacy of users or staff
- Don't perform attacks that disrupt service availability (no DoS, no flooding, no spam)
- Give us reasonable time to fix before public disclosure
Specifically, you're authorized to:
- Probe public-facing endpoints
- Test the agent binary locally
- Review source code (it's public)
- Use the free plan for testing (please don't sign up under multiple identities to abuse limits)
Bounty#
We don't currently run a paid bug bounty program — we're bootstrapped and small. We do offer:
- Public credit in our security advisories
- GritivaCore Pro for life for confirmed High/Critical findings (one account, you keep it)
- Swag when we have it (T-shirt, sticker pack)
- A genuine thank-you and reference if you'd like one for your portfolio
Once we're cash-flow positive (target: late 2026), we'll launch a formal bounty.
Disclosure timeline#
We aim for 90 days from confirmed report to public disclosure. Most fixes ship in 14-30 days; the longer window allows for coordinated disclosure with downstream users when relevant.
If 90 days passes without a fix and there's no compelling reason to extend (e.g. coordinated CVE), the reporter is free to publish.
Past advisories#
| Date | Title | Severity | Credit |
|---|---|---|---|
| (none yet) | (none yet) | — | — |
We've had no public security advisories to date. We'll publish here when we do.
Contact#
- Security: [email protected] — PGP available
- General privacy: [email protected]
- Trust & safety: [email protected]