Gridware Logo

Vulnerability Disclosure Policy

Effective Date: 23 September 2024

Last Updated: 23 September 2024

At Gridware, we take the security of our infrastructure, products and services very seriously. Protecting our clients, users and ensuring that vulnerabilities are responsibly disclosed and addressed is of utmost importance to us. This page outlines our policies and processes for reporting, acknowledging, and mitigating security vulnerabilities.

  1. Scope of Disclosure

This policy applies to any vulnerability affecting our:

If you identify a vulnerability within these products or services, we encourage you to follow the responsible disclosure guidelines outlined below.

Please note that there is no reward scheme for discovering a vulnerability.

  1. Reporting Vulnerabilities

We encourage security researchers, partners, and customers to report any vulnerabilities they find.

How to Report:

Required Information:

  1. Acknowledgment and Response

Upon receiving your vulnerability report, we will:

  1. Our Commitment

We commit to:

  1. Disclosure Timeline

We follow a coordinated disclosure timeline:

  1. Public Announcements

We will publicly disclose the details of the vulnerability once:

We will publish security advisories on the Gridware Threat Blog.

  1. CVE Assignment

As a CVE Numbering Authority (CNA), we will assign a CVE ID to validated vulnerabilities. If you’re a researcher reporting a vulnerability, you will be credited for the CVE submission (unless you prefer anonymity).

  1. Do Not Report the Following:
  1. Out-of-Scope

The following are considered out-of-scope:

  1. Safe Harbor

We value the contributions of security researchers and commit to:

  1. Contact Us

For any questions regarding this policy or to submit a report:

Email: ict.security@gridware.com.au

We appreciate your efforts in helping us maintain a secure environment for all users.