At Graylog, Inc., we are committed to the security of our systems, software and services. We value the contributions of the security community in helping us protect our users and data. If you believe you have discovered a vulnerability in our systems, we encourage you to report it responsibly.
This policy applies to:
It does not apply to:
If you discover a security vulnerability, please:
When testing, you must not:
What We Commit To:
We appreciate and recognize contributions that help improve the security of our systems. While we do not currently operate a paid bug bounty program, we may offer public acknowledgment to researchers who responsibly disclose valid issues. We may also provide limited compensation in the form of our choosing should we deem the contribution worthy of such compensation.
Safe Harbor
When conducting vulnerability research within the guidelines of this policy:
Please send all vulnerability reports to:
[email protected]
If you need to encrypt sensitive information, please use our PGP key found in the link in our pgp-key.txt file in the link listed in the security.txt file on our main web site.