Responsible Disclosure Policy
1. Scope
This policy applies to security vulnerabilities found in:
- The Gravitas platform — app.withgravitas.io
- The Gravitas public website — withgravitas.io
- Gravitas APIs
The following are out of scope:
- Third-party services and integrations (report these to the relevant provider)
- Social engineering or phishing attacks against Gravitas employees
- Physical security testing
- Denial of service (DoS/DDoS) attacks
- Spam or email abuse
2. How to report
Send your report to security@withgravitas.io. Please include:
- A description of the vulnerability and its potential impact
- Step-by-step instructions to reproduce the issue
- Any supporting evidence (screenshots, proof-of-concept code, HTTP requests)
- Your contact information for follow-up
If the vulnerability is particularly sensitive, you may encrypt your report using our PGP public key, available at /pgp-key.txt.
3. Safe harbour
Laneden Ltd will not pursue civil or criminal legal action against security researchers who:
- Act in good faith and within the scope of this policy
- Make reasonable efforts to avoid privacy violations, data destruction, and service disruption
- Do not exploit vulnerabilities beyond the minimum necessary to demonstrate the issue
- Report vulnerabilities promptly and do not disclose them publicly before an agreed remediation timeline
If at any point you are unsure whether your research complies with this policy, contact us at security@withgravitas.io before proceeding.
4. Guidelines for researchers
When conducting security research against Gravitas systems, you must:
- Not access, modify, or delete data belonging to other users. If you inadvertently access real user data, stop testing immediately and report the access
- Not perform denial of service testing of any kind
- Not use automated scanning tools (such as vulnerability scanners or fuzzers) without prior written approval
- Not publicly disclose vulnerabilities before the agreed remediation timeline has elapsed
- Limit proof-of-concept to the minimum necessary to demonstrate the issue — do not exfiltrate data, escalate privileges beyond what is needed, or chain vulnerabilities unnecessarily
5. Our commitment
When you submit a valid vulnerability report, we commit to:
- Acknowledge receipt within 72 hours
- Provide status updates during our investigation and remediation process
- Resolve critical vulnerabilities within 90 days (we aim for faster where possible)
- Notify you when the vulnerability has been fixed
6. Recognition
We do not currently operate a formal bug bounty programme. However, we value the work of security researchers and are happy to:
- Credit you publicly on our website (with your permission)
- Provide a reference or verification of your findings for your professional portfolio
We may introduce a formal bounty programme in the future.