All legal documents

Grey Collective Inc.

Responsible Disclosure Policy

1. Introduction

Grey Collective Inc. (“Grey Collective”, “we”, “us” or “our”) is committed to maintaining the security, integrity and reliability of our systems and digital services.

We appreciate the efforts of security researchers and members of the security community who responsibly report potential security vulnerabilities.

This Responsible Disclosure Policy explains how security vulnerabilities should be reported to Grey Collective and how such reports will be handled.

2. Purpose

The purpose of this Policy is to encourage the responsible reporting of genuine security vulnerabilities so that they may be investigated and, where appropriate, remediated before they can be exploited.

Grey Collective supports responsible security research conducted in good faith.

3. Reporting a Security Vulnerability

If you believe you have identified a legitimate security vulnerability affecting Grey Collective, please notify us as soon as reasonably practicable.

Reports should include, where possible:

  • a description of the vulnerability;
  • the affected system or service;
  • the steps required to reproduce the issue;
  • the potential security impact;
  • supporting evidence, including screenshots where appropriate;
  • your contact information.

Reports should be submitted to:

Email: greycollectiveinc@gmail.com

4. Good Faith Research

Grey Collective considers security research to be conducted in good faith where the researcher:

  • acts responsibly;
  • reports vulnerabilities privately;
  • avoids unnecessary disruption;
  • avoids compromising the confidentiality, integrity or availability of systems;
  • does not access, modify, delete or disclose information without authorisation;
  • provides Grey Collective with a reasonable opportunity to investigate and remediate the issue before any public disclosure.

5. Prohibited Activities

This Policy does not authorise any person to:

  • access information without permission;
  • access Client information;
  • access confidential information;
  • bypass authentication mechanisms;
  • exploit a vulnerability for personal benefit;
  • install malware;
  • introduce malicious code;
  • conduct denial-of-service attacks;
  • interfere with the availability of services;
  • modify data without authorisation;
  • socially engineer Grey Collective personnel;
  • physically access facilities without permission;
  • perform any activity that violates applicable law.

Any unlawful activity may result in legal action and referral to the appropriate authorities.

6. Confidentiality

Grey Collective requests that reported vulnerabilities remain confidential until:

  • the vulnerability has been investigated;
  • appropriate remediation has been implemented where necessary; or
  • Grey Collective provides written permission for public disclosure.

Premature public disclosure may increase security risks for Grey Collective, its Clients and other affected parties.

7. Our Commitment

Where a report is submitted in good faith, Grey Collective will use reasonable efforts to:

  • acknowledge receipt of the report;
  • investigate the reported vulnerability;
  • assess the potential impact;
  • implement appropriate remediation where necessary;
  • communicate with the reporting party where appropriate.

Grey Collective cannot guarantee that every reported issue will constitute a security vulnerability or require remediation.

8. No Reward Programme

Grey Collective does not currently operate a bug bounty or financial reward programme.

Submission of a vulnerability report does not create any entitlement to compensation, payment or other reward unless expressly agreed in writing.

9. Scope

This Responsible Disclosure Policy applies only to systems, services and digital assets owned or operated by Grey Collective.

It does not apply to third-party systems, software, infrastructure or services, even where such services are integrated into Grey Collective’s operations.

Reports relating solely to third-party products should be directed to the relevant provider.

10. Reservation of Rights

Grey Collective reserves the right to:

  • determine whether a reported issue constitutes a security vulnerability;
  • determine the appropriate remediation;
  • determine the appropriate timing of any remediation;
  • decline to investigate reports that are incomplete, malicious, abusive or outside the scope of this Policy.

Nothing contained in this Policy constitutes permission to access, test or interfere with any system in a manner that would otherwise be unlawful.

11. Changes to this Policy

Grey Collective reserves the right to amend this Responsible Disclosure Policy at any time.

Any revised version shall become effective upon publication.

12. Governing Law

This Responsible Disclosure Policy shall be governed by and interpreted in accordance with the laws of the Republic of South Africa.

Nothing contained in this Policy limits any rights or obligations that cannot lawfully be excluded under applicable legislation.

13. Contact Information

For all security vulnerability reports or questions regarding this Responsible Disclosure Policy, please contact:

Grey Collective Inc.

Email: greycollectiveinc@gmail.com

Country of Operation: Republic of South Africa

End of Responsible Disclosure Policy