Vulnerability Disclosure Policy
How to report a security problem in GIMLabs
Last updated: 22 September 2026
1. Why this exists
If you have found a security problem in GIMLabs, we would rather hear about it than not. This page tells you how to tell us, what we will do about it, and what we ask of you while you are looking.
It applies to anyone: a customer, one of their contractors, a security researcher, or someone who stumbled on something by accident. You do not need permission in advance and you do not need an existing relationship with us.
2. How to report something
Email support@gimlabs.io with “Security” in the subject line. We also publish this address at /.well-known/security.txt.
Please include as much of this as you can:
- What you found, and which part of GIMLabs it affects.
- The steps to reproduce it. A short screen recording is often faster than a written description.
- What an attacker could actually do with it.
- Any account, project or location IDs you used, so we can find the same thing in our logs.
- How you would like to be credited, if you would like to be.
Write in English if you can. If you cannot, send it anyway and we will manage.
3. What we will do
- We will acknowledge your report within one business day, in line with our Support and Availability commitments. Our support hours are Monday to Friday, 9:00 to 17:00 UK time.
- We will tell you whether we think it is a real issue, and roughly how serious we think it is, within five business days.
- We will keep you updated while we work on it, and we will tell you when it is fixed.
- If the issue affects customer data, we will follow the breach process in our Data Processing Agreement, including notifying affected customers without undue delay and in any event within 72 hours.
- If you would like credit, we will offer it once the fix is live. You can also ask to stay anonymous.
We are a small team. We will be honest with you about timescales rather than optimistic.
4. What we ask of you
- Give us a reasonable chance to fix it before you tell anyone else. We do not set a fixed deadline, but please talk to us before going public.
- Do not access, change, download or delete other people’s data. If you need to prove an issue is real, use your own account or ask us for a test account. Stop as soon as you have confirmed the problem.
- Do not degrade the service. No denial-of-service testing, no load or stress testing, no automated scanning that generates significant traffic, and no spam or social engineering of our staff or customers.
- Do not use physical attacks, or attacks on our staff, offices or suppliers.
- If you do come across personal data, stop, do not keep a copy, and tell us what you saw.
5. Our commitment to you
If you follow this policy, we will treat your report as an authorised contribution to the security of GIMLabs. We will not bring a legal claim against you, and we will not report you to the police or to any other authority, in connection with your research.
If a third party brings a claim against you for something you did while following this policy, we will make it clear that you were acting within it.
This is a commitment about how we will behave. It cannot, and does not, waive rights belonging to anyone other than us. In particular it does not give you permission to touch data belonging to our customers.
6. What is in scope
Anything we run on a `gimlabs.io` domain, including the marketing site, the platform apps and the public API.
7. What is out of scope
These are not things we will treat as vulnerabilities, so please do not spend your time on them:
- Missing security headers or cookie flags with no demonstrated impact.
- Results from an automated scanner, sent without a working proof of concept.
- Reports that an email address can be enumerated at sign-up, or the absence of rate limiting, without a demonstrated attack.
- Missing SPF, DKIM or DMARC records, and general email spoofing reports.
- Self-inflicted issues that need the victim to paste something into their own browser console.
- Vulnerabilities in a browser, operating system or third-party service that we do not control. Report those to the people who do.
- Anything that needs physical access to an unlocked device that is already signed in.
- Denial of service, resource exhaustion, and anything that depends on flooding us with traffic.
- Social engineering of our staff or our customers.
If you are not sure whether something is in scope, send it anyway and say so.
8. We do not pay for reports
We do not run a bug bounty and we do not pay for vulnerability reports. We are a small company and we would rather be straight with you about that up front than have you discover it after doing the work.
What we will do is fix the problem, keep you informed, and credit you if you want to be credited.
9. Contact
support@gimlabs.io
GIMLabs is a trading name of SoTech Studio Limited, registered in England and Wales, company number 13906561, Cedar Barn, White Lodge, Walgrave, Northampton, NN6 9PY.
Questions about this policy? Get in touch.