Responsible Reporting

Gradr.ai aims to keep its services safe for everyone, and security is our highest priority. If you believe you have found a vulnerability in Gradr.ai, we encourage you to contact us at security@gradr.ai. We will confirm receipt of your vulnerability report and strive to send you regular updates about our work to resolve the issue.


Responsible Disclosure

You should give us reasonable time to investigate and mitigate an issue you report before publishing any information about the report or sharing such information with others. You should not exploit a security issue you discover for any reason, and avoid privacy violations as well as interruption or degradation of our services.


Acknowledgement

We may reward submissions that help us keep our services safe to use, provided they comply with this responsible disclosure policy. Whether a reward is offered or not is entirely at our discretion.


Scope

Systems in scope:

  • Gradr.ai website

  • Gradr.ai web application

  • Gradr.ai Google Docs extension

  • Gradr.ai API


Out of scope:

  • Denial of Service attacks (DoS/DDoS)

  • Spam or social engineering techniques

  • Reports from automated scanning tools.