GraceDNS
Log in Setup Now

Vulnerability Disclosure Policy#

Last updated: 2026-08-20

botBrains GmbH welcomes security research on GraceDNS. If you believe you have found a vulnerability, we want to hear from you.

Reporting#

We aim to acknowledge reports within 3 business days and to give you an initial assessment within 10 business days.

Scope#

In scope:

Out of scope:

Rules of engagement#

Safe harbor#

We will not initiate legal action or file criminal complaints against researchers who act in good faith, stay within this policy's scope and rules, and give us reasonable time to remediate. This includes research that would otherwise implicate the German Computer Crime provisions (ยงยง 202a ff. StGB), to the extent we can lawfully waive claims. If a third party initiates action against you for good-faith research under this policy, we will make it known that your actions were authorized by us.

Disclosure window#

We ask for a 90-day coordinated disclosure window from your report. If we ship a fix earlier, you are free to publish earlier; if remediation genuinely needs longer, we will explain why and agree on a new date with you. We credit researchers who wish to be named.

No bounty program (yet)#

We do not currently run a paid bug bounty program. We will say thank you, credit you if you like, and take your report seriously.