Security & disclosure
Report a security issue.
If you believe you have found a vulnerability affecting our public website, please report it privately so we can investigate.
Report a vulnerability
Email support@granwel.com with the subject “Security vulnerability report”. Include the affected URL, a description of the issue, its potential impact and the minimum steps needed to reproduce it.
Do not send personal data, credentials or sensitive evidence in your initial email. If sensitive details are needed, ask us to agree a suitable way to share them first.
Responsible research
- Keep testing limited to the public Granwel website. This policy does not authorise testing of third-party services or other systems.
- Do not access, download, alter or retain data beyond the minimum needed to demonstrate a problem. Stop if you encounter someone else’s personal data.
- Do not disrupt services, perform destructive testing, run denial-of-service attacks, introduce malware or attempt social engineering.
- Do not use a vulnerability to gain persistent access or move into other systems.
- Report privately and allow a reasonable opportunity for investigation and remediation before public disclosure. Please coordinate disclosure with us.
What to expect
We will assess reports and may ask for clarification. We do not promise a fixed response or resolution time. This is a disclosure channel; no bug bounty, payment or legal safe harbour is offered by this policy.
Machine-readable contact details are available in security.txt.