Security Acknowledgements
Last reviewed:
Guitard Inc. recognizes security researchers who help protect its systems and users through responsible, good-faith vulnerability disclosure.
Acknowledgements are published only with the reporter’s explicit consent.
Eligibility
A researcher may be acknowledged when:
- they are the first person to report a previously unknown vulnerability;
- the report identifies a reproducible security issue affecting an in-scope Guitard Inc. system;
- the report provides enough information to investigate the issue;
- the researcher followed the Security Policy;
- the report contributed materially to understanding or resolving the vulnerability; and
- publication would not create an unreasonable risk to users, Guitard Inc., or a third party.
When multiple researchers independently report the same vulnerability, Guitard Inc. will normally acknowledge the first complete and actionable report. Additional researchers may be acknowledged when their work contributed materially different information.
Reports That Are Normally Ineligible
Acknowledgement is not normally provided for:
- duplicate or previously known vulnerabilities;
- scanner output without manual validation;
- findings without a credible security impact;
- missing security headers without a demonstrated vulnerability;
- software-version observations without evidence that the affected condition is exploitable;
- self-XSS or issues requiring implausible user interaction;
- spam, phishing simulations, or social-engineering findings;
- reports involving prohibited or disruptive testing;
- vulnerabilities affecting only third-party systems;
- reports copied from another researcher; or
- reports submitted with a demand for payment, publicity, or other compensation.
Guitard Inc. may acknowledge an otherwise ineligible report when it provides exceptional defensive value.
Publication and Privacy
Before publishing an acknowledgement, we will ask the reporter to approve:
- the name, pseudonym, or organization to display;
- an optional professional-profile or website link;
- a concise description of the vulnerability;
- the month or date of acknowledgement; and
- any advisory or CVE reference, when applicable.
Researchers may choose to be listed anonymously. We will not publish an email address, personal information, technical exploit details, or other sensitive information without explicit permission.
A reporter may request removal of their name or link from this page by contacting security@guitard.ca. Historical security information may be retained when necessary, but we will make reasonable efforts to honour privacy requests.
Compensation
This is a vulnerability disclosure and recognition program, not a bug bounty program.
Guitard Inc. does not currently promise financial rewards, gifts, employment, or other compensation for reports. Any discretionary recognition does not establish an obligation for current or future submissions.
Current Acknowledgements
No eligible reports have been publicly acknowledged yet.
Report a Vulnerability
Before performing security testing or submitting a report, review the Security Policy.
Reports may be sent to security@guitard.ca.