Security policy & reporting vulnerabilities
GRIDer's security policy —how to report a vulnerability, what we commit to, which versions are supported and the list of published security advisories— lives on the main website:
This page is a short summary. If anything here differs from the policy on grider.xyz, the policy on grider.xyz applies.
Report a vulnerability
Write to the security contact published on the security policy page. The same address is in the machine-readable security.txt files of grider.xyz and of this site.
If you can, include:
- the affected component: the GRIDer version (shown in the app), the installer, the updater, or the affected site or server (grider.xyz, docs, get, registry or scanner);
- a description of the problem and its impact;
- steps to reproduce it and, if you have one, a proof of concept;
- whether you know or suspect that it is being exploited;
- how to contact you.
Please report vulnerabilities privately, not in public Discord channels or on social networks, and never include real keys, seed phrases or other people's data.
What happens next
- We acknowledge receipt within 72 hours.
- We keep you informed while we assess and fix the problem.
- We agree with you when to publish the details, generally once a fix is available and users have had reasonable time to install it.
Good-faith research that follows the rules of the policy (no access to third parties' data, no denial of service, no social engineering) is welcome: read the full rules on grider.xyz/security.
Supported versions
During each licence we support and publish security updates for the current version and the one immediately before it. You apply updates on your own instance: see Updating GRIDer.
How security advisories are published
- On grider.xyz/security, also as machine-readable JSON at grider.xyz/security/advisories.json.
- As a notice inside the app.
- On your instance's Telegram, if you have configured it.
- When necessary, by email to affected customers.
Protecting your own instance is covered in Protecting your instance. GRIDer will never ask for your seed phrase or private keys, and nobody from GRIDer needs access to your server.