Security Acknowledgements

Last reviewed:

Guitard Inc. recognizes security researchers who help protect its systems and users through responsible, good-faith vulnerability disclosure.

Acknowledgements are published only with the reporter’s explicit consent.

Eligibility

A researcher may be acknowledged when:

When multiple researchers independently report the same vulnerability, Guitard Inc. will normally acknowledge the first complete and actionable report. Additional researchers may be acknowledged when their work contributed materially different information.

Reports That Are Normally Ineligible

Acknowledgement is not normally provided for:

Guitard Inc. may acknowledge an otherwise ineligible report when it provides exceptional defensive value.

Publication and Privacy

Before publishing an acknowledgement, we will ask the reporter to approve:

Researchers may choose to be listed anonymously. We will not publish an email address, personal information, technical exploit details, or other sensitive information without explicit permission.

A reporter may request removal of their name or link from this page by contacting security@guitard.ca. Historical security information may be retained when necessary, but we will make reasonable efforts to honour privacy requests.

Compensation

This is a vulnerability disclosure and recognition program, not a bug bounty program.

Guitard Inc. does not currently promise financial rewards, gifts, employment, or other compensation for reports. Any discretionary recognition does not establish an obligation for current or future submissions.

Current Acknowledgements

No eligible reports have been publicly acknowledged yet.

Report a Vulnerability

Before performing security testing or submitting a report, review the Security Policy.

Reports may be sent to security@guitard.ca.