Vulnerability Disclosure Policy
The security of our customers' data is our highest priority. We welcome and appreciate security researchers who help us keep GraphCapsule secure.
How to report a vulnerability
If you believe you have found a security vulnerability in GraphCapsule, please report it to us at:
[email protected]Please include as much detail as possible: description of the vulnerability, steps to reproduce, potential impact, and any proof-of-concept code if available.
Our response process
What happens after you submit a report.
Acknowledgment within 48 hours
We will confirm receipt of your report and provide a point of contact for follow-up communication.
Investigation within 7 days
Our security team will investigate the reported vulnerability and determine its validity and severity.
Status updates
We will keep you informed about the progress and provide an estimated timeline for remediation.
Fix and disclosure
Once the vulnerability is fixed, we will notify you and coordinate any public disclosure if appropriate.
Scope
In scope
- graphcapsule.cloud web application
- GraphCapsule API endpoints
- Authentication and authorization flaws
- Data exposure or leakage
- Cross-site scripting (XSS)
- SQL / NoSQL injection
- Server-side request forgery (SSRF)
- Privilege escalation
Out of scope
- Denial of service (DoS/DDoS) attacks
- Social engineering / phishing
- Physical security attacks
- Attacks against third-party services
- Spam or email abuse
- Clickjacking on pages with no sensitive actions
- Missing security headers without exploit
- Software version disclosure
Rules of engagement
We ask researchers to follow these guidelines.
- Do not access, modify, or delete data belonging to other users.
- Do not perform actions that could impact service availability for other users.
- Use only your own test accounts for testing. Do not test against accounts you do not own.
- Stop testing and report immediately if you encounter any user data.
- Allow reasonable time for us to fix the vulnerability before any public disclosure.
- Provide sufficient detail in your report for us to reproduce and verify the issue.
We will not pursue legal action against security researchers who follow this policy in good faith.
