Skip to content

Security: grimdalltech/grimdall-os

Security

SECURITY.md

Security Policy

Grimdall is a security product, so integrity matters.

Reporting a vulnerability

If you find a vulnerability, do not open a public issue.

Email: security@grimdall.com

Include:

  • What you found
  • How to reproduce it
  • Why it matters
  • Any logs or screenshots you can share safely

Review policy

  • Changes to the policy engine require careful review.
  • Secret handling and redaction logic is security-sensitive.
  • We aim to acknowledge reports within 48 hours and triage within one week.

There aren't any published security advisories