Vulnerability Disclosure Policy

Gilion takes the security of our platform and our customers’ data seriously. We welcome reports from security researchers and others who believe they have found a vulnerability in our services. This policy explains how to report one and what you can expect from us.

How to report

Email security@gilion.com with:

  • a description of the vulnerability and its potential impact

  • the affected URL, endpoint or component

  • step-by-step instructions to reproduce it, ideally with a proof of concept

  • your name or handle, if you would like us to know who reported it

Please write in English or Swedish, and do not include any personal or customer data you may have come across beyond what is strictly needed to show the issue.

Scope

In scope

  • Gilion web applications and APIs on *.gilion.com, including investor.gilion.com, app.gilion.com, canvas.gilion.com and api.gilion.com

Out of scope

  • Our third-party providers’ own services (for example Google, Microsoft, Cloudflare, Datadog). Please report those to the provider directly.

  • Social engineering, phishing or physical attacks against Gilion staff or offices

  • Denial-of-service, load or volumetric testing

  • Reports produced only by automated scanners, without a demonstrated, exploitable impact

  • Best-practice or configuration findings without a demonstrated security impact, for example missing HTTP security headers, cookie flags, SPF/DKIM/DMARC records, clickjacking on pages without sensitive actions, TLS cipher preferences, or software version disclosure

Rules of engagement

When investigating, please:

  • only test against accounts you own or have explicit permission to use

  • stop as soon as you have confirmed a vulnerability, and do not access, modify, download or delete data that does not belong to you

  • not degrade, disrupt or attempt to gain persistent access to our services

  • not use the vulnerability beyond what is needed to demonstrate it

  • keep the details confidential until we have resolved the issue and agreed on disclosure with you

What happens after you report

  1. Acknowledgement. We aim to acknowledge your report within 5 business days.

  2. Triage. Our Head of Security assesses the report, confirms whether it is valid, and rates its severity. Confirmed vulnerabilities are handled through our incident and vulnerability management processes.

  3. Remediation. We fix confirmed vulnerabilities according to their severity, in line with our internal remediation timelines, and let you know when the issue has been resolved.

  4. Disclosure. We are happy to coordinate public disclosure with you once a fix is in place.

Safe harbour

If you act in good faith and follow this policy, we will consider your research authorised. We will not pursue or support legal action against you, and we will not report you to law enforcement, for that research. If a third party brings legal action against you for activities that were conducted in accordance with this policy, we will make it known that your actions were authorised by us.

If you are unsure whether a planned activity is within this policy, ask us at security@gilion.com before you start.

Rewards

Gilion does not currently run a bug bounty programme and does not offer monetary rewards for reports. With your permission, we are glad to credit researchers who report valid vulnerabilities.

Last updated: October 5, 2026