Responsible Disclosure Policy

Last updated: 6 April 2026
Contents
  1. Scope
  2. How to report
  3. Safe harbour
  4. Guidelines for researchers
  5. Our commitment
  6. Recognition

1. Scope

This policy applies to security vulnerabilities found in:

The following are out of scope:

2. How to report

Send your report to security@withgravitas.io. Please include:

If the vulnerability is particularly sensitive, you may encrypt your report using our PGP public key, available at /pgp-key.txt.

3. Safe harbour

Laneden Ltd will not pursue civil or criminal legal action against security researchers who:

If at any point you are unsure whether your research complies with this policy, contact us at security@withgravitas.io before proceeding.

4. Guidelines for researchers

When conducting security research against Gravitas systems, you must:

5. Our commitment

When you submit a valid vulnerability report, we commit to:

6. Recognition

We do not currently operate a formal bug bounty programme. However, we value the work of security researchers and are happy to:

We may introduce a formal bounty programme in the future.