Quote

Coordinated disclosure policy.

We welcome reports of security vulnerabilities. Please follow this policy when you research and report issues. Version 1.1 — Effective 2026-07-31.

POLICY

What we accept and how we respond.

Scope

  • All publicly reachable services and assets operated by Grilli OÜ (private limited company, registered in Estonia), unless explicitly excluded.

How to report

  • Email security@grillisecurity.com with the affected asset, impact, reproduction steps, and any supporting evidence
  • Reference /.well-known/security.txt for current contacts
  • Do not send credentials, customer data, or exploit archives in the first email; we will arrange a protected transfer channel when needed

Response targets

  • Acknowledgement within three business days
  • Initial validation status or a request for more information within ten business days
  • Progress updates at least every ten business days while a confirmed issue remains open
  • Remediation and disclosure timing are set by severity, exposure, and operational risk, and coordinated with the reporter
RULES

Safe harbour and limits.

Safe harbour

  • Research that follows this policy is authorised by Grilli OÜ for the systems in scope
  • We will not initiate or recommend legal action, or refer the activity to law enforcement, for good-faith research that follows this policy
  • Do not access customer data, degrade service, or retain data
  • Make a good-faith effort to avoid privacy violations and service disruption
  • No extortion: do not make demands for payment as a condition for disclosure

Out of scope

  • Denial of Service or volumetric attacks
  • High-volume automated scanning, or scanning that degrades service; coordinate potentially disruptive tests first
  • Clickjacking on non-sensitive pages, missing SPF/DMARC reports, or best-practice advisories without exploitability

Testing constraints

  • Do not access or exfiltrate live customer data; if you encounter it accidentally, stop immediately and report the details securely
  • Avoid production impact; coordinate high-risk tests with us in advance
  • Retain only the minimum data required to document the vulnerability; delete it once the report is submitted
THANKS

Recognition.

  • We appreciate the security community. With permission, we recognise contributors here.
  • To be listed, please tell us your preferred name/handle after coordinated disclosure.
  • We do not currently operate a public bug-bounty programme. Recognition does not imply a monetary award.
ACTIVE INCIDENT?