Cookie Settings

We use cookies to ensure the basic functionality of our website. Essential cookies (theme preference, session, consent status) are required and cannot be disabled. Optional cookies for analytics and payment processing are only set with your explicit consent. Privacy Policy

Responsible Disclosure

Vulnerability Disclosure Policy

The security of our customers' data is our highest priority. We welcome and appreciate security researchers who help us keep GraphCapsule secure.

How to report a vulnerability

If you believe you have found a security vulnerability in GraphCapsule, please report it to us at:

[email protected]

Please include as much detail as possible: description of the vulnerability, steps to reproduce, potential impact, and any proof-of-concept code if available.

Our response process

What happens after you submit a report.

Acknowledgment within 48 hours

We will confirm receipt of your report and provide a point of contact for follow-up communication.

Investigation within 7 days

Our security team will investigate the reported vulnerability and determine its validity and severity.

Status updates

We will keep you informed about the progress and provide an estimated timeline for remediation.

Fix and disclosure

Once the vulnerability is fixed, we will notify you and coordinate any public disclosure if appropriate.

Scope

In scope

  • graphcapsule.cloud web application
  • GraphCapsule API endpoints
  • Authentication and authorization flaws
  • Data exposure or leakage
  • Cross-site scripting (XSS)
  • SQL / NoSQL injection
  • Server-side request forgery (SSRF)
  • Privilege escalation

Out of scope

  • Denial of service (DoS/DDoS) attacks
  • Social engineering / phishing
  • Physical security attacks
  • Attacks against third-party services
  • Spam or email abuse
  • Clickjacking on pages with no sensitive actions
  • Missing security headers without exploit
  • Software version disclosure

Rules of engagement

We ask researchers to follow these guidelines.

  • Do not access, modify, or delete data belonging to other users.
  • Do not perform actions that could impact service availability for other users.
  • Use only your own test accounts for testing. Do not test against accounts you do not own.
  • Stop testing and report immediately if you encounter any user data.
  • Allow reasonable time for us to fix the vulnerability before any public disclosure.
  • Provide sufficient detail in your report for us to reproduce and verify the issue.

We will not pursue legal action against security researchers who follow this policy in good faith.