Aller au contenu
shadgramers

Responsible Disclosure

Coordinated vulnerability disclosure policy — ShadGramers

Last updated: May 2026

Purpose

This policy sets out the conditions under which ShadGramers accepts security vulnerability reports from external researchers, and the commitments we make in return.

Safe harbour clause

ShadGramers undertakes not to bring civil or criminal proceedings against any security researcher who complies with the conditions below.

This clause applies under French law (Criminal Code Art. 323-1 — automated data processing systems) and European law (NIS2 Directive, GDPR). It cannot apply in jurisdictions where the researcher's legal protection cannot be guaranteed contractually.

Conditions applying to the researcher

Safe harbour protection applies only if the researcher:

  • Reports the vulnerability to ShadGramers before any public disclosure.
  • Does not exploit the vulnerability beyond what is strictly necessary to demonstrate its existence and impact.
  • Does not access third-party data (ShadGramers customers, end users) beyond what is strictly necessary.
  • Does not destroy, alter or retain any data they have accessed.
  • Allows ShadGramers a reasonable period (at least 5 working days for acknowledgement, 90 days for a fix) before public disclosure.
  • Acts in good faith, without malicious intent, without extortion, without reselling the vulnerability.
  • Does not carry out DoS/DDoS attacks, social engineering, or attacks against third-party systems.

ShadGramers' commitments

  • Acknowledge receipt of the report within 5 working days at most.
  • Inform the researcher of the investigation status within 15 working days.
  • Not disclose the researcher's identity without their explicit agreement.
  • Fix identified vulnerabilities within a reasonable period (critical: 30 days, high: 60 days, medium: 90 days).
  • Publicly credit the researcher, by name or anonymously at their choice (no financial reward: the programme is not funded).
  • Provide on request a written attestation of the finding, usable as a professional reference.

France — Criminal Code Art. 323-1 to 323-7 (fraudulent access to an automated data processing system). Article 323-1(4), introduced by the 2024 Military Programming Act, provides an exemption from liability for persons who notify a vulnerability in good faith to ANSSI and to the entity concerned. ShadGramers encourages this channel and does not treat a coordinated report as unauthorised access.

European Union — The NIS2 Directive (EU 2022/2555) encourages Member States to establish coordinated disclosure mechanisms. This policy is aligned with ENISA (European Union Agency for Cybersecurity) recommendations on coordinated vulnerability disclosure.

GDPR — If your research involves personal data, you must not store, copy or transmit it. Report any accidental exposure to us immediately.

What remains out of scope

ShadGramers reserves the right to take action against anyone who:

  • Accesses real customer data without demonstrated strict necessity.
  • Sells or attempts to sell the vulnerability to a third party.
  • Uses the vulnerability for unauthorised personal or commercial purposes.
  • Engages in extortion or threatens disclosure to obtain a ransom.
  • Breaches this policy after having been explicitly informed of it.

Contact

For any report: security@shadgramers.tech
For legal questions about this policy: legal@shadgramers.tech

See the reporting programme (scope, recognition, process)