Security Policy

Effective date
Last reviewed
Policy version
1.0

Purpose

Guitard Inc. takes the security of its systems, services, and users seriously. We welcome reports from security researchers and members of the public who believe they have discovered a security vulnerability affecting a system operated by Guitard Inc.

This policy explains:

This is a vulnerability disclosure program, not a bug bounty program. Guitard Inc. does not currently offer financial rewards for reports.

Reporting a Vulnerability

Send vulnerability reports to security@guitard.ca.

Reports may be submitted anonymously. However, providing a working contact method will allow us to request additional information and provide status updates.

Sensitive reports may be encrypted using the OpenPGP public key published at guitard.ca/.well-known/pgp-key.txt.

The key is associated with an authorized Guitard Inc. security contact even if its identity differs from the reporting address above.

Please do not send passwords, authentication tokens, private keys, personal information, or unnecessarily sensitive data through unencrypted email.

Information to Include

Please provide enough information for us to reproduce and assess the vulnerability. When possible, include:

Please remove or redact unrelated personal and sensitive information from all evidence.

Reports generated entirely by automated scanners should include manual validation demonstrating a credible security impact.

Scope

This policy applies to public-facing systems and services that are owned and operated by Guitard Inc., including:

An asset is in scope only when Guitard Inc. has the legal and operational authority to authorize testing of it.

The following are outside the scope of this policy:

If you are uncertain whether an asset is in scope, contact security@guitard.ca before testing it.

Vulnerabilities in third-party components may still be reported to us when they directly affect a Guitard Inc. service. Testing of the third party itself must follow that party’s authorization and disclosure policy.

Authorized Research

Guitard Inc. considers research authorized under this policy when all of the following conditions are met:

Benign proof-of-concept testing and reasonable, non-disruptive automated testing are permitted when conducted in accordance with these requirements.

Prohibited Activity

This policy does not authorize:

If testing causes unintended impact, stop immediately and include the details in your report.

Sensitive Data

If you encounter personal, confidential, proprietary, authentication, or other sensitive information:

  1. Stop testing immediately.
  2. Do not continue browsing, searching, or enumerating the information.
  3. Do not copy or retain more information than is minimally necessary to demonstrate the issue.
  4. Do not share the information with any third party.
  5. Report the issue promptly using the encrypted reporting option when appropriate.
  6. Securely delete retained information when requested or once it is no longer needed for coordinated remediation.

Whenever possible, demonstrate the vulnerability using your own account and synthetic or non-sensitive data.

What You Can Expect From Us

Guitard Inc. will make reasonable efforts to:

These are service targets rather than guarantees. Complex vulnerabilities, dependencies on third parties, and operational constraints may require additional time.

Reports that present an immediate or material risk may be prioritized ahead of other submissions.

Coordinated Disclosure

Please give Guitard Inc. a reasonable opportunity to investigate and remediate a reported vulnerability before making it public.

The disclosure date should be agreed upon by Guitard Inc. and the reporter based on:

As an initial guideline, we may request up to 90 days from confirmation to remediate a vulnerability. This period may be shortened for actively exploited vulnerabilities or extended by mutual agreement when remediation requires additional work.

Public disclosure must not include personal information, authentication material, confidential information, or information that would unnecessarily expose users to harm.

Safe Harbour

When a researcher complies with this policy and acts in good faith, Guitard Inc. will consider that research authorized for the systems over which it has authority.

For compliant research, Guitard Inc. does not intend to initiate or support legal action against the researcher. If a third party initiates legal action and the researcher has complied with this policy, Guitard Inc. may, where appropriate and legally permitted, confirm that the research was conducted in accordance with this policy.

This policy:

If you are uncertain whether proposed testing is permitted, contact us before proceeding.

Acknowledgement

Researchers who submit a previously unknown, valid security vulnerability and comply with this policy may be recognized on the Security Acknowledgements page.

Acknowledgement is voluntary and requires the reporter’s consent. Acknowledgement does not create an entitlement to payment or other compensation.

Policy Changes

Guitard Inc. may update this policy as its systems, risks, or disclosure practices evolve. The effective date and version number will be updated when material changes are made.

Questions about this policy may be sent to security@guitard.ca.