Aller au contenu
shadgramers

Responsible disclosure

ShadGramers encourages responsible disclosure of security vulnerabilities. We treat every report seriously and publicly credit the researchers who help us improve the security of our services.

This programme is not funded. We are a young company: we do not pay bounties, and we would rather say so plainly than publish a reward table we could not honour. The recognition we do offer is described below. If you are looking for a paid programme, better to know before you invest your time.

In scope

portail.shadgramers.tech

Customer portal — authentication, API, dashboard

vitrine.shadgramers.tech

Public website, forms, Stripe payment

apps/orchestrator

Queue service — provisioning, jobs

auth.shadgramers.tech

Keycloak — single sign-on, OIDC, tenant provisioning

/api/v1/*

Public endpoints with an API token

webhooks

Stripe, Mattermost, third-party integrations

Out of scope

Rate-limit fuzzing and volumetric testing (DoS / DDoS)
Social engineering (phishing, vishing) against our teams or customers
Physical attacks against our infrastructure
Vulnerabilities in third-party software (Nextcloud, Keycloak, etc.) — report them upstream
Self-XSS (injection into your own data, with no cross-tenant impact)
Expired TLS certificates or sub-optimal TLS configuration with no demonstrated impact
Missing security headers without proof of real exploitation
Attacks requiring physical access to the end user's machine

What we offer in return

SeverityExamplesOur commitment
CriticalRemote code execution, cross-tenant authentication bypass, database exfiltration, full privilege escalation, SSRF reaching the internal networkAcknowledgement within 24 h, priority fix, public named credit, written attestation of the finding, CVE request where applicable
HighStored XSS affecting other users, limited SSRF, partial privilege escalation (viewer → admin), CSRF on an authenticated sensitive action, SQL injection with data impactAcknowledgement within 48 h, public named credit, written attestation of the finding
MediumDisclosure of sensitive information (email addresses, internal identifiers), reflected XSS with limited impact, CSRF on a non-sensitive function, rate-limit bypass with real impactPublic named credit, mention in the fix notes
LowMinor security defects, misconfigurations without immediate impact, non-sensitive technical information exposedPublic thanks

Public credit is named or anonymous, at your choice. No financial consideration is paid today, and we do not promise a retroactive bounty: if the programme is ever funded, it will be announced on this page and will apply only to later reports.

Reporting process

  1. 1Send an email to security@shadgramers.tech with the subject [SECURITY] and a short description.
  2. 2In the body: description of the vulnerability, reproduction steps, estimated impact, environment tested.
  3. 3If the matter is sensitive (high or critical), encrypt it with our PGP key (fingerprint below).
  4. 4Do not exploit the vulnerability beyond what is strictly necessary to demonstrate that the flaw exists.
  5. 5Wait for our acknowledgement (5 working days at most) before any public disclosure.
  6. 6Coordinated public disclosure: we aim for 90 days after the report, or sooner if the fix is available.

Contact and PGP

PGP fingerprint:

PGP key not published yet

A report template is available on request. See also our responsible disclosure policy.

Hall of fame

Be the first researcher to appear here.

This programme is covered by our safe harbour clause . No legal action will be taken against researchers acting in good faith and respecting this framework.