Coordinated disclosure policy.
We welcome reports of security vulnerabilities. Please follow this policy when you research and report issues. Version 1.1 — Effective 2026-07-31.
POLICY
What we accept and how we respond.
Scope
- All publicly reachable services and assets operated by Grilli OÜ (private limited company, registered in Estonia), unless explicitly excluded.
How to report
- Email security@grillisecurity.com with the affected asset, impact, reproduction steps, and any supporting evidence
- Reference /.well-known/security.txt for current contacts
- Do not send credentials, customer data, or exploit archives in the first email; we will arrange a protected transfer channel when needed
Response targets
- Acknowledgement within three business days
- Initial validation status or a request for more information within ten business days
- Progress updates at least every ten business days while a confirmed issue remains open
- Remediation and disclosure timing are set by severity, exposure, and operational risk, and coordinated with the reporter
RULES
Safe harbour and limits.
Safe harbour
- Research that follows this policy is authorised by Grilli OÜ for the systems in scope
- We will not initiate or recommend legal action, or refer the activity to law enforcement, for good-faith research that follows this policy
- Do not access customer data, degrade service, or retain data
- Make a good-faith effort to avoid privacy violations and service disruption
- No extortion: do not make demands for payment as a condition for disclosure
Out of scope
- Denial of Service or volumetric attacks
- High-volume automated scanning, or scanning that degrades service; coordinate potentially disruptive tests first
- Clickjacking on non-sensitive pages, missing SPF/DMARC reports, or best-practice advisories without exploitability
Testing constraints
- Do not access or exfiltrate live customer data; if you encounter it accidentally, stop immediately and report the details securely
- Avoid production impact; coordinate high-risk tests with us in advance
- Retain only the minimum data required to document the vulnerability; delete it once the report is submitted
THANKS
Recognition.
- ✓We appreciate the security community. With permission, we recognise contributors here.
- ✓To be listed, please tell us your preferred name/handle after coordinated disclosure.
- ✓We do not currently operate a public bug-bounty programme. Recognition does not imply a monetary award.
