← Trust center

Responsible disclosure

Report a vulnerability

Think you have found a flaw in graal? Write to security@graal.systems. We acknowledge, fix, and keep you informed until publication.

Process

From report to publication

  1. 01

    You report

    Describe the flaw, the affected version, its impact and the steps to reproduce it.

  2. 02

    We acknowledge

    Within five business days, with a first analysis and a named contact.

  3. 03

    We fix

    A fix is released for maintained versions, with a security note.

  4. 04

    We publish together

    The vulnerability is made public no later than 90 days after the report, on a date agreed with you.

Scope

The graal software and this website

In scope

The graal platform (console, API, MCP server, runtime images, Helm chart) and the graal.systems website.

To report elsewhere

A graal installation operated by an organization: report to that organization directly, and copy us if the flaw lies in the software.

Good faith

Our commitments, and yours

  • No legal action against research conducted in good faith, in line with this policy
  • Credit in the security note, if you wish
  • A written answer from a person on the team
  • Do not access data that is not yours, nor keep it
  • Do not degrade the service: no denial of service, no social engineering
  • Allow time for a fix before any publication

security.txt

A machine-readable contact

The /.well-known/security.txt file, compliant with RFC 9116, gives the contact address, the response languages (French and English) and the link to this policy.

A security question?

The security team also answers your CISO’s questionnaires.