If you believe you have found a security issue in any GRIFF AI surface, email security@griff.run. Include a description, reproduction steps, the affected URL or artifact, and any timeline constraints you need us to respect.
What we promise: we will acknowledge receipt, work the issue in good faith, and credit you in any public remediation note unless you ask us not to. We do not currently run a paid bug bounty.
What we will not do: pursue legal action against good-faith research that respects the boundaries below.
- Do not access, modify, or exfiltrate data that is not yours.
- Do not run automated scanners that would consume production capacity meaningfully (the rate limit in section 4 will catch you anyway).
- Do not publicly disclose until we have had a reasonable chance to remediate — 90 days is the baseline; we will discuss shorter windows for already-public issues.
Honest SLA: this is a single-operator product. We do not yet publish a triage-time SLA. Expect an acknowledgement within a few business days for the foreseeable future. If that is not acceptable for your use case, route the issue through the contact form and flag it as security.