Security Policy
Purpose
Guitard Inc. takes the security of its systems, services, and users seriously. We welcome reports from security researchers and members of the public who believe they have discovered a security vulnerability affecting a system operated by Guitard Inc.
This policy explains:
- which systems may be tested;
- which research activities are authorized;
- how to report a vulnerability;
- how Guitard Inc. will handle reports; and
- the conditions under which Guitard Inc. considers security research to have been conducted in good faith.
This is a vulnerability disclosure program, not a bug bounty program. Guitard Inc. does not currently offer financial rewards for reports.
Reporting a Vulnerability
Send vulnerability reports to security@guitard.ca.
Reports may be submitted anonymously. However, providing a working contact method will allow us to request additional information and provide status updates.
Sensitive reports may be encrypted using the OpenPGP public key published at guitard.ca/.well-known/pgp-key.txt.
The key is associated with an authorized Guitard Inc. security contact even if its identity differs from the reporting address above.
Please do not send passwords, authentication tokens, private keys, personal information, or unnecessarily sensitive data through unencrypted email.
Information to Include
Please provide enough information for us to reproduce and assess the vulnerability. When possible, include:
- the affected domain, URL, service, or component;
- the vulnerability type;
- a description of the security impact;
- detailed, repeatable steps to reproduce the issue;
- a benign proof of concept, screenshot, or supporting evidence;
- the date and approximate time of testing;
- the source IP address and test-account identifier, if relevant;
- whether personal, confidential, or otherwise sensitive information was encountered;
- any actions already taken that may have affected the system or its data;
- your preferred contact method;
- your acknowledgement preference, if any; and
- your intended disclosure timeline.
Please remove or redact unrelated personal and sensitive information from all evidence.
Reports generated entirely by automated scanners should include manual validation demonstrating a credible security impact.
Scope
This policy applies to public-facing systems and services that are owned and operated by Guitard Inc., including:
guitard.ca; and- subdomains of
guitard.cathat are demonstrably operated by Guitard Inc.
An asset is in scope only when Guitard Inc. has the legal and operational authority to authorize testing of it.
The following are outside the scope of this policy:
- third-party products, platforms, and hosted services not operated by Guitard Inc.;
- systems belonging to customers, suppliers, service providers, or other third parties;
- personal accounts, devices, or information belonging to another person;
- systems that cannot reasonably be confirmed as belonging to Guitard Inc.; and
- any system that expressly publishes a different security policy.
If you are uncertain whether an asset is in scope, contact security@guitard.ca before testing it.
Vulnerabilities in third-party components may still be reported to us when they directly affect a Guitard Inc. service. Testing of the third party itself must follow that party’s authorization and disclosure policy.
Authorized Research
Guitard Inc. considers research authorized under this policy when all of the following conditions are met:
- the research is conducted in good faith;
- the tested system is within scope;
- testing is limited to the minimum activity needed to confirm the vulnerability;
- the researcher uses accounts and data they own or have explicit permission to use;
- the research avoids harm to users, systems, data, and service availability;
- the researcher stops immediately if sensitive information, unintended access, or service disruption is encountered;
- the vulnerability is reported promptly and directly to Guitard Inc.; and
- vulnerability details are not publicly disclosed before coordinated disclosure has occurred.
Benign proof-of-concept testing and reasonable, non-disruptive automated testing are permitted when conducted in accordance with these requirements.
Prohibited Activity
This policy does not authorize:
- social engineering, phishing, pretexting, or impersonation;
- physical attacks or attempts to access Guitard Inc. facilities;
- denial-of-service or distributed denial-of-service testing;
- excessive traffic, disruptive scanning, or resource-exhaustion testing;
- password spraying, credential stuffing, brute-force attacks, or MFA-fatigue attacks;
- testing with stolen, leaked, or otherwise unauthorized credentials;
- accessing accounts, communications, or information belonging to another person;
- intentionally downloading, copying, modifying, deleting, or retaining data that is not your own;
- installing malware, ransomware, cryptocurrency miners, web shells, backdoors, or other persistence mechanisms;
- lateral movement or using one compromised system to access another;
- altering system configurations or weakening security controls;
- sending spam or unsolicited communications;
- testing third-party systems without the third party’s authorization;
- publicly disclosing a vulnerability before coordinated disclosure; or
- any activity that violates applicable law or exceeds the authorization granted by this policy.
If testing causes unintended impact, stop immediately and include the details in your report.
Sensitive Data
If you encounter personal, confidential, proprietary, authentication, or other sensitive information:
- Stop testing immediately.
- Do not continue browsing, searching, or enumerating the information.
- Do not copy or retain more information than is minimally necessary to demonstrate the issue.
- Do not share the information with any third party.
- Report the issue promptly using the encrypted reporting option when appropriate.
- Securely delete retained information when requested or once it is no longer needed for coordinated remediation.
Whenever possible, demonstrate the vulnerability using your own account and synthetic or non-sensitive data.
What You Can Expect From Us
Guitard Inc. will make reasonable efforts to:
- acknowledge a valid report within five business days;
- provide an initial assessment within ten business days;
- communicate significant status changes;
- provide an update at least every 30 days while a confirmed vulnerability remains unresolved;
- work with the reporter to understand and reproduce the issue;
- prioritize remediation according to risk, exploitability, and potential impact;
- coordinate disclosure with affected third parties when necessary; and
- acknowledge eligible researchers when they request public recognition.
These are service targets rather than guarantees. Complex vulnerabilities, dependencies on third parties, and operational constraints may require additional time.
Reports that present an immediate or material risk may be prioritized ahead of other submissions.
Coordinated Disclosure
Please give Guitard Inc. a reasonable opportunity to investigate and remediate a reported vulnerability before making it public.
The disclosure date should be agreed upon by Guitard Inc. and the reporter based on:
- the vulnerability’s severity and exploitability;
- evidence of active exploitation;
- the complexity of remediation;
- risks to users or third parties; and
- dependencies on vendors or service providers.
As an initial guideline, we may request up to 90 days from confirmation to remediate a vulnerability. This period may be shortened for actively exploited vulnerabilities or extended by mutual agreement when remediation requires additional work.
Public disclosure must not include personal information, authentication material, confidential information, or information that would unnecessarily expose users to harm.
Safe Harbour
When a researcher complies with this policy and acts in good faith, Guitard Inc. will consider that research authorized for the systems over which it has authority.
For compliant research, Guitard Inc. does not intend to initiate or support legal action against the researcher. If a third party initiates legal action and the researcher has complied with this policy, Guitard Inc. may, where appropriate and legally permitted, confirm that the research was conducted in accordance with this policy.
This policy:
- does not authorize testing of third-party systems;
- does not provide immunity from applicable law;
- does not waive the rights of third parties;
- does not authorize access to information beyond what is minimally necessary to demonstrate a vulnerability; and
- does not bind law-enforcement agencies, regulators, courts, or other independent parties.
If you are uncertain whether proposed testing is permitted, contact us before proceeding.
Acknowledgement
Researchers who submit a previously unknown, valid security vulnerability and comply with this policy may be recognized on the Security Acknowledgements page.
Acknowledgement is voluntary and requires the reporter’s consent. Acknowledgement does not create an entitlement to payment or other compensation.
Policy Changes
Guitard Inc. may update this policy as its systems, risks, or disclosure practices evolve. The effective date and version number will be updated when material changes are made.
Questions about this policy may be sent to security@guitard.ca.