Vulnerability Disclosure Policy
Report security concerns privately to security@socialgryd.com, including the affected service, minimal reproduction steps, impact and contact details. Avoid personal data or credentials in reports. We do not claim an available PGP key, guaranteed response time or paid bounty programme.
1. Research boundaries
Only test accounts and systems you are authorised to access. Do not access, copy or alter another person's data; disrupt availability; socially engineer staff/users; persist access; or attack a third-party provider. Stop if sensitive information is encountered and report minimal metadata. Follow applicable law.
2. Coordinated handling
Allow reasonable time for investigation and remediation before public disclosure of exploit details. We welcome good-faith reports and will assess them fairly. This policy cannot authorise conduct against third parties or grant immunity from applicable law. We do not promise future HackerOne/Bugcrowd programmes or legal safe-harbour protections beyond our authority.
