Guidelines for reporting security vulnerabilities to Granola
We take our systems’ security seriously, and we value input from the security community. If you’ve discovered a vulnerability, we appreciate your help in disclosing it to us.
Make every effort to avoid privacy violations, degradation of our user’s experience, disruption to production systems, and destruction of data during security testing
Perform research only within the scope set out below
Use the identified communication channels to disclose vulnerability information to us
Keep information about any vulnerabilities you’ve discovered confidential between yourself and us until we’ve had 90 days to resolve the issue
If you believe you’ve found a security vulnerability in one of our products or platforms that is within the bounds of this program, please contact us at security@granola.so with a detailed description of the vulnerability and steps to reproduce it.