Report a security issue, the right way.
We welcome good-faith security research that helps keep Golbi and its organizations safe. This policy explains how to report and what to expect.
About this policy
Last updated June 2, 2026. If you believe you have found a security vulnerability in Golbi, we want to hear from you. This policy describes what is in scope, how to report, and the protections we offer to researchers who act in good faith.
How to report a vulnerability.
Send your report to security@golbi.app. Please include enough detail to reproduce the issue, such as the affected area, steps, and any proof-of-concept. Give us a reasonable opportunity to investigate and fix the issue before disclosing it publicly.
What is in and out of scope.
In scope are vulnerabilities in Golbi's own website and application that could affect the security of the service or its data.
Protection for good-faith research.
We will not pursue legal action against researchers who act in good faith, follow this policy, avoid harm to Golbi or its users, and give us a reasonable time to respond. We consider activity conducted under this policy to be authorized, and we will work with you rather than against you. If you are unsure whether something is allowed, ask us first at security@golbi.app.
Testing that is not allowed.
What you can expect from us.
We aim to acknowledge new reports within a few business days, keep you informed as we investigate, and let you know when the issue is resolved. Timelines depend on the complexity and severity of the issue.
Thank you.
We are grateful to researchers who help keep Golbi safe. With your permission, we are happy to acknowledge your contribution once an issue is resolved. Golbi may update this policy from time to time, and changes will be posted on this page with the date above.
Help us keep group data safe.
Set up the basics now and bring your team in when you are ready.