Security ยท Responsible Disclosure

Coordinated disclosure policy.

How to report a security issue to GIRD, and what to expect from us.

How to report

Send an email to security@gird.ai (preferred), or to hello@gird.ai. Please include reproduction steps, the affected URLs or components, and an estimate of the impact. A PGP key is available on request for encrypted reports.

What you can expect from us

  • Acknowledgement within 2 business days of your initial report.
  • A triage assessment within 5 business days, including a severity rating and a proposed timeline.
  • High and critical issues fixed within 30 days of triage wherever possible; we'll keep you informed if a fix needs longer.
  • Updates when the fix is scheduled and when it ships.
  • Public credit, at your discretion, on this page once a fix has shipped.

Scope

  • The Argus app for Mac, in every edition, including the free download.
  • The Argus sign-in and telemetry services.
  • The GIRD console.
  • gird.ai and its subdomains.
  • Any other GIRD source artefact, container image, or binary we distribute.

Out of scope: third-party services we rely on (for example our hosting provider, font provider, and CDN); volumetric or denial-of-service testing; social engineering of our team; and physical attacks.

Safe harbour

If you act in good faith, follow this policy, avoid privacy violations, the destruction of data, and disruption of service, and give us a reasonable time to remediate before any public disclosure. If you do, we will not pursue legal action against you for your research. We consider good-faith security research authorised under this policy.

No paid bug bounty

We do not currently run a paid bounty programme. On request, we provide a written reference letter.