Trust

Vulnerability Disclosure Policy

Last updated: March 14, 2026

At GoTryGPT ("we", "us", or "our"), we value the security of our platform and the safety of our users. This Vulnerability Disclosure Policy (VDP) describes how we work with security researchers who report potential vulnerabilities in our services at https://gotrygpt.com (the "Services"). We encourage responsible, coordinated disclosure and will work with you to understand and address valid findings.

1. Scope

We are interested in reports of security vulnerabilities that affect the confidentiality, integrity, or availability of our Services, our infrastructure, or our users' data. In-scope assets include:

  • Our main web application and APIs at gotrygpt.com
  • Authentication and session handling
  • Data handling, storage, and transmission
  • Third-party integrations we use (e.g. Stripe, Cognito) only as they relate to our implementation and configuration

Examples of Qualifying Vulnerabilities

  • Cross-site scripting (XSS)
  • SQL injection or NoSQL injection
  • Insecure direct object references (IDOR) / broken access control
  • Authentication or session management flaws
  • Server-side request forgery (SSRF)
  • Remote code execution (RCE)
  • Sensitive data exposure
  • Cross-site request forgery (CSRF) on state-changing actions
  • Privilege escalation

2. Out of Scope

The following are generally out of scope for this program:

  • Issues in third-party services, software, or websites we do not control
  • Social engineering, phishing, or physical attacks
  • Denial-of-service (DoS) or resource-exhaustion attacks
  • Vulnerabilities that require physical or privileged access to a user's device or account
  • Known issues in outdated browsers or dependencies where we have no control
  • Low-impact issues such as missing security headers without a demonstrated exploit
  • Self-XSS that cannot be used to exploit other users
  • Missing DMARC, SPF, or DKIM records without a demonstrated attack
  • Clickjacking on pages with no sensitive actions
  • CSRF on logout, login, or other non-state-changing actions
  • Content spoofing or text injection without demonstrated impact
  • Reports generated by automated scanners or tools without manual validation or a clear proof of exploitability
  • Rate limiting issues without demonstrated security impact
  • Descriptive error messages or stack traces that do not expose sensitive data

If you are unsure whether something is in scope, please report it and we will evaluate it.

3. Rules of Engagement

When conducting security research under this policy, you must follow these rules:

  • Only test against accounts you own or have explicit permission to test
  • Do not access, modify, or delete data belonging to other users
  • If you accidentally encounter sensitive data (personal information, credentials, etc.), stop testing immediately, do not save or share the data, and report it to us
  • Do not perform testing that could degrade the availability or performance of our Services for other users
  • Do not use automated vulnerability scanners at scale without prior written authorization
  • Do not publicly disclose vulnerability details until we have had a reasonable opportunity to address the issue (see Section 6)
  • Make a good-faith effort to avoid privacy violations, destruction of data, or disruption of our services

4. How to Report

Please send your report to support@gotrygpt.com with the subject line "Security Vulnerability Report". Include:

  • A clear description of the vulnerability and affected component
  • Steps to reproduce the issue
  • Impact assessment (what an attacker could achieve)
  • Any proof-of-concept, screenshots, or video recordings (avoid sharing sensitive user data)
  • The environment used (browser, OS, tools) if relevant to reproduction
  • Your contact information so we can follow up

If you would like to communicate securely, please mention this in your initial report and we will coordinate an encrypted channel.

5. What to Expect

  • Acknowledgment: We will acknowledge receipt of your report within 3 business days.
  • Assessment: We will review, validate, and triage the finding within 10 business days of acknowledgment.
  • Updates: We will keep you informed of our progress at reasonable intervals, and no less than once every 30 days while the issue is being addressed.
  • Resolution: We aim to remediate confirmed vulnerabilities within 90 days, depending on severity and complexity. Critical issues will be prioritized.
  • Verification: We may ask for your help to verify that a fix resolves the reported issue.

These timelines are targets and may vary based on the severity and complexity of the issue. We will communicate any delays transparently.

6. Confidentiality & Coordinated Disclosure

We ask that you keep all details of any discovered vulnerability confidential until we have confirmed the issue is resolved or 90 days have passed since your initial report, whichever comes first. This coordinated disclosure approach ensures that users are protected before details become public.

We will coordinate with you before any public disclosure and will credit you (with your consent) in any public advisory or acknowledgment. If we are unable to resolve the issue within 90 days, we will work with you in good faith to agree on an appropriate disclosure timeline.

7. Safe Harbor

We consider security research conducted in accordance with this policy to be authorized conduct. If you comply with this policy, we will not pursue civil or criminal legal action or file a complaint with law enforcement against you in connection with your research.

Specifically, we consider research conducted under this policy to be:

  • Authorized under applicable computer trespass laws, and we will not initiate or support legal claims against you for accidental, good-faith violations of this policy
  • Authorized under anti-circumvention provisions, and we will not bring claims against you for circumvention of technology controls
  • Exempt from restrictions in our Terms of Service that would otherwise interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy
  • Lawful, helpful to the overall security of the internet, and conducted in good faith

You are expected, as always, to comply with all applicable laws. If at any point you have concerns or are uncertain whether your security research is consistent with this policy, please submit a report through the channel described above before proceeding further. We may still need to take technical action to protect our systems and users (e.g., blocking abusive traffic), but we will not pursue legal action for good-faith research.

8. Recognition

We appreciate the time and effort of researchers who help us improve our security. While we do not currently offer a monetary bug bounty program, we may acknowledge your contribution (with your consent) in a hall of fame or similar recognition. We will not disclose your identity without your permission.

9. Changes to This Policy

We may update this Vulnerability Disclosure Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Your continued participation in security research under this policy after changes are posted constitutes acceptance of those changes.

10. Contact

For questions about this policy or to report a vulnerability, contact us at support@gotrygpt.com. For general security practices, see our Security page.