Responsible Disclosure

Report a security issue, the right way.

We welcome good-faith security research that helps keep Golbi and its organizations safe. This policy explains how to report and what to expect.

About this policy

Last updated June 2, 2026. If you believe you have found a security vulnerability in Golbi, we want to hear from you. This policy describes what is in scope, how to report, and the protections we offer to researchers who act in good faith.

Reporting

How to report a vulnerability.

Send your report to security@golbi.app. Please include enough detail to reproduce the issue, such as the affected area, steps, and any proof-of-concept. Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.

Scope

What is in and out of scope.

In scope are vulnerabilities in Golbi's own website and application that could affect the security of the service or its data.

In scope: authentication, authorization, and tenant-isolation flaws in Golbi.
In scope: injection, data exposure, and similar issues in Golbi's application.
Out of scope: issues in third-party services and infrastructure we do not control.
Out of scope: reports that require an already-compromised device or account, or that rely on social engineering.
Out of scope: missing best-practice headers or settings with no demonstrated security impact.
Safe harbor

Protection for good-faith research.

We will not pursue legal action against researchers who act in good faith, follow this policy, avoid harm to Golbi or its users, and give us a reasonable time to respond. We consider activity conducted under this policy to be authorized, and we will work with you rather than against you. If you are unsure whether something is allowed, ask us first at security@golbi.app.

Rules

Testing that is not allowed.

Do not run denial-of-service or load-testing attacks.
Do not access, modify, or delete data that does not belong to you, and use only test accounts where possible.
Do not use social engineering, phishing, or physical attacks against Golbi or its staff.
Do not degrade the experience of other users or organizations.
Stop testing and report immediately if you encounter personal data that is not yours.
Response

What you can expect from us.

We aim to acknowledge new reports within a few business days, keep you informed as we investigate, and let you know when the issue is resolved. Timelines depend on the complexity and severity of the issue.

Recognition

Thank you.

We are grateful to researchers who help keep Golbi safe. With your permission, we are happy to acknowledge your contribution once an issue is resolved. Golbi may update this policy from time to time, and changes will be posted on this page with the date above.

Help us keep group data safe.

Set up the basics now and bring your team in when you are ready.