Vulnerability Disclosure Policy

Version 2.0 | Published: 7 September 2026

Beta policy update. Published 7 September 2026. Updated contractual terms apply to new registrations on express acceptance and to existing accounts from 8 October 2026 after notice and any required fresh acceptance. Existing rights are preserved. Corrected operator information and new safety/privacy controls apply as they are released; notices describe those controls and do not create consent by themselves. Read the complete update.

Report security concerns privately to security@socialgryd.com, including the affected service, minimal reproduction steps, impact and contact details. Avoid personal data or credentials in reports. We do not claim an available PGP key, guaranteed response time or paid bounty programme.

1. Research boundaries

Only test accounts and systems you are authorised to access. Do not access, copy or alter another person's data; disrupt availability; socially engineer staff/users; persist access; or attack a third-party provider. Stop if sensitive information is encountered and report minimal metadata. Follow applicable law.

2. Coordinated handling

Allow reasonable time for investigation and remediation before public disclosure of exploit details. We welcome good-faith reports and will assess them fairly. This policy cannot authorise conduct against third parties or grant immunity from applicable law. We do not promise future HackerOne/Bugcrowd programmes or legal safe-harbour protections beyond our authority.