Coordinated disclosure
Vulnerability Disclosure Policy
How to report a suspected security issue while minimizing harm and unnecessary data access.
Pre-publication draft: this document is not an approved public-beta contract. Publication and open registration remain disabled.
Document: disclosure
Version: 2026-07-22-beta-readiness-1
Effective date: 2026-07-22
Content hash: 7677c76abaa79768a8640ca38c815a906adbdfa9420dc44ed29525ed27b3ea42
Security: security@gutmask.xyz
Reporting
Send a concise private report to security@gutmask.xyz with affected surface, impact, reproduction steps, and enough evidence to validate the issue.
- Minimize data collection and stop when the issue is demonstrated.
- Do not include secrets in the subject line or use third-party data as a test fixture.
Permitted and prohibited testing
Good-faith testing must stay within accounts and systems you own or are explicitly authorized to test.
- No denial of service, persistence, social engineering, malware, spam, physical attacks, privacy invasion, or disruption.
- No access, modification, deletion, or exfiltration beyond the minimum proof.
- Third-party services and customer deployments are out of scope without their separate authorization.
Coordination and safe harbor
The operator intends to acknowledge actionable reports and coordinate remediation on a reasonable-efforts basis. No bounty or response deadline is promised unless a separate program says otherwise.
- Good-faith research consistent with this policy will not be treated as malicious by the operator, subject to applicable law and third-party rights.
- Public disclosure should be coordinated to reduce harm.