Responsible disclosure
Report a vulnerability
Think you have found a flaw in graal? Write to security@graal.systems. We acknowledge, fix, and keep you informed until publication.
Process
From report to publication
01
You report
Describe the flaw, the affected version, its impact and the steps to reproduce it.
02
We acknowledge
Within five business days, with a first analysis and a named contact.
03
We fix
A fix is released for maintained versions, with a security note.
04
We publish together
The vulnerability is made public no later than 90 days after the report, on a date agreed with you.
Scope
The graal software and this website
In scope
The graal platform (console, API, MCP server, runtime images, Helm chart) and the graal.systems website.
To report elsewhere
A graal installation operated by an organization: report to that organization directly, and copy us if the flaw lies in the software.
Good faith
Our commitments, and yours
- No legal action against research conducted in good faith, in line with this policy
- Credit in the security note, if you wish
- A written answer from a person on the team
- Do not access data that is not yours, nor keep it
- Do not degrade the service: no denial of service, no social engineering
- Allow time for a fix before any publication
security.txt
A machine-readable contact
The /.well-known/security.txt file, compliant with RFC 9116, gives the contact address, the response languages (French and English) and the link to this policy.
A security question?
The security team also answers your CISO’s questionnaires.