Responsible disclosure
ShadGramers encourages responsible disclosure of security vulnerabilities. We treat every report seriously and publicly credit the researchers who help us improve the security of our services.
This programme is not funded. We are a young company: we do not pay bounties, and we would rather say so plainly than publish a reward table we could not honour. The recognition we do offer is described below. If you are looking for a paid programme, better to know before you invest your time.
In scope
portail.shadgramers.tech
Customer portal — authentication, API, dashboard
vitrine.shadgramers.tech
Public website, forms, Stripe payment
apps/orchestrator
Queue service — provisioning, jobs
auth.shadgramers.tech
Keycloak — single sign-on, OIDC, tenant provisioning
/api/v1/*
Public endpoints with an API token
webhooks
Stripe, Mattermost, third-party integrations
Out of scope
What we offer in return
| Severity | Examples | Our commitment |
|---|---|---|
| Critical | Remote code execution, cross-tenant authentication bypass, database exfiltration, full privilege escalation, SSRF reaching the internal network | Acknowledgement within 24 h, priority fix, public named credit, written attestation of the finding, CVE request where applicable |
| High | Stored XSS affecting other users, limited SSRF, partial privilege escalation (viewer → admin), CSRF on an authenticated sensitive action, SQL injection with data impact | Acknowledgement within 48 h, public named credit, written attestation of the finding |
| Medium | Disclosure of sensitive information (email addresses, internal identifiers), reflected XSS with limited impact, CSRF on a non-sensitive function, rate-limit bypass with real impact | Public named credit, mention in the fix notes |
| Low | Minor security defects, misconfigurations without immediate impact, non-sensitive technical information exposed | Public thanks |
Public credit is named or anonymous, at your choice. No financial consideration is paid today, and we do not promise a retroactive bounty: if the programme is ever funded, it will be announced on this page and will apply only to later reports.
Reporting process
- 1Send an email to security@shadgramers.tech with the subject [SECURITY] and a short description.
- 2In the body: description of the vulnerability, reproduction steps, estimated impact, environment tested.
- 3If the matter is sensitive (high or critical), encrypt it with our PGP key (fingerprint below).
- 4Do not exploit the vulnerability beyond what is strictly necessary to demonstrate that the flaw exists.
- 5Wait for our acknowledgement (5 working days at most) before any public disclosure.
- 6Coordinated public disclosure: we aim for 90 days after the report, or sooner if the fix is available.
Contact and PGP
PGP fingerprint:
PGP key not published yetA report template is available on request. See also our responsible disclosure policy.
Hall of fame
This programme is covered by our safe harbour clause . No legal action will be taken against researchers acting in good faith and respecting this framework.