Responsible Disclosure Policy Grasple

This page has been changed on 21 December 2021 and created on 10 August 2021.

IMPORTANT NOTES

  • The bug bounty program has been discontinued since 21 December 2021, 06:00AM Central European Time. We are evaluating the experiment of having a bug bounty program and based on the analysis develop a new security program in the future. Any updates on this will be communicated on this page. Critical to understand is:
    • it is not allowed anymore to perform any security research on our domains without our explicit approval;
    • reports shared with us are not eligible for any reward, since the bug bounty program has been discontinued;
    • all accounts created by researchers in the past are deleted on 21 December 2021 and any accounts having suspect behaviour will be deleted in the future;

At Grasple, we do consider the security of our systems a top priority. Therefore, if you discover a vulnerability while using Grasple, we do encourage you to let us know about it such that we can take steps to address it as quickly as possible. In that case, please do the following:

  • E-mail your findings to cert@grasple.com. If possible, please encrypt your findings using our PGP key to prevent this critical information from falling into the wrong hands.

Please be aware: this is not a bug bounty program. There are no rewards for reports shared with us. Performing security research is not allowed under the current terms & services and will be flagged as illegal behaviour.

Questions and feedback

Regarding questions or feedback related to this Responsible Disclosure policy, you can contact us via email:

security@grasple.com