Vulnerability Disclosure Program (VDP)
At GSearchAI, security and customer data protection are paramount. Our Vulnerability Disclosure Program provides clear guidelines for security researchers and customers to conduct responsible vulnerability research and disclose security issues across our platform and integrations, including our Slack App.
Does our Vulnerability Disclosure Program cover our Slack App?
Yes, absolutely. The GSearchAI Vulnerability Disclosure Program explicitly covers our Slack application, including all Slack bot endpoints, event subscriptions, slash command handlers (/gsearch), interactive Block Kit components, OAuth 2.0 authorization flows, and backend knowledge retrieval connectors.
1. Program Scope
The following properties and integrations are in scope for our Vulnerability Disclosure Program:
Bot mentions (@GSearchAI), slash commands, Slack OAuth redirects, event webhook receivers, and interactive block actions.
Web application dashboard (https://gsearchai.com), user authentication, API endpoints, and database knowledge connectors.
Out of Scope:
- Distributed Denial of Service (DDoS/DoS) attacks against our infrastructure.
- Spam, phishing, or social engineering attacks targeting employees or customers.
- Physical security attacks against facilities or data centers.
- Third-party services or infrastructure not directly operated by Gramosoft Private Limited.
2. How to Report a Vulnerability
If you identify a security flaw or potential vulnerability in our Slack app or platform, please submit your findings directly to our security engineering team:
You can also submit security reports through our public Support & Help Portal without needing to create an account.
- Clear description and severity of the vulnerability.
- Step-by-step reproduction steps or proof-of-concept (PoC).
- Affected URL, Slack endpoint, or component.
- Any potential impact or risk assessment.
3. Response & Remediation SLA
Our security team is committed to timely triage, communication, and resolution:
We confirm receipt of your report and assign a security triage engineer.
We validate the vulnerability and determine the severity rating.
Critical vulnerabilities patched within 7 business days, high within 14 business days.
4. Safe Harbor Guarantee
We consider security research conducted in accordance with this policy to be authorized. Gramosoft Private Limited will not pursue civil action or initiate legal complaints against researchers who:
- Act in good faith to identify vulnerabilities without causing disruption to services or systems.
- Do not view, alter, extract, delete, or destroy customer or organizational data.
- Provide us reasonable time to remediate the vulnerability prior to public disclosure.
- Comply with applicable local, state, and international laws.
Questions regarding our Security & VDP?
Reach our team directly at gsearchai@gmail.com