← Back to App

Security & Responsible Disclosure

Gia Marine Intelligence LLC

Report a security issue: security@giamarine.com

Expected response time: within 2 business days. For critical issues (active exploitation, exposed credentials, data exfiltration risk), please put CRITICAL in the subject line.

Our Commitment

We take the security of our systems and the safety of our customers' data seriously. We welcome reports from independent security researchers, customers, and the broader community, and we will work with you in good faith to investigate, remediate, and credit verified findings.

Scope

Issues reported under this policy must affect one of the following Gia Marine Intelligence assets:

Out of scope

Issues in the following are out of scope for this disclosure program, though we still appreciate hearing about them:

What to Include in a Report

To help us triage and respond quickly, please include:

Safe Harbor

Gia Marine Intelligence considers security research conducted in accordance with this policy to be:

We will not pursue legal action against researchers who:

If law enforcement initiates a legal investigation against you because of your good-faith compliance with this policy, we will take steps to make it known that your actions were authorized.

What We Will Do

Rewards

Gia Marine does not currently operate a paid bug bounty program. We may, at our discretion, offer recognition (public credit, swag, or a discretionary thank-you payment) for high-impact reports. We will be transparent if and when a formal paid program launches.

Encryption

For sensitive reports, you may request our PGP public key in your initial email and we will respond with one. Future: a published PGP key will be linked here once SOC 2 onboarding is complete.

Machine-readable security.txt

A machine-readable contact file per RFC 9116 is available at /.well-known/security.txt.

Last updated: [DATE] · Terms of Service · Privacy Policy · Acceptable Use