Vulnerability Disclosure Policy
Gilion takes the security of our platform and our customers’ data seriously. We welcome reports from security researchers and others who believe they have found a vulnerability in our services. This policy explains how to report one and what you can expect from us.
How to report
Email security@gilion.com with:
a description of the vulnerability and its potential impact
the affected URL, endpoint or component
step-by-step instructions to reproduce it, ideally with a proof of concept
your name or handle, if you would like us to know who reported it
Please write in English or Swedish, and do not include any personal or customer data you may have come across beyond what is strictly needed to show the issue.
Scope
In scope
Gilion web applications and APIs on *.gilion.com, including investor.gilion.com, app.gilion.com, canvas.gilion.com and api.gilion.com
Out of scope
Our third-party providers’ own services (for example Google, Microsoft, Cloudflare, Datadog). Please report those to the provider directly.
Social engineering, phishing or physical attacks against Gilion staff or offices
Denial-of-service, load or volumetric testing
Reports produced only by automated scanners, without a demonstrated, exploitable impact
Best-practice or configuration findings without a demonstrated security impact, for example missing HTTP security headers, cookie flags, SPF/DKIM/DMARC records, clickjacking on pages without sensitive actions, TLS cipher preferences, or software version disclosure
Rules of engagement
When investigating, please:
only test against accounts you own or have explicit permission to use
stop as soon as you have confirmed a vulnerability, and do not access, modify, download or delete data that does not belong to you
not degrade, disrupt or attempt to gain persistent access to our services
not use the vulnerability beyond what is needed to demonstrate it
keep the details confidential until we have resolved the issue and agreed on disclosure with you
What happens after you report
Acknowledgement. We aim to acknowledge your report within 5 business days.
Triage. Our Head of Security assesses the report, confirms whether it is valid, and rates its severity. Confirmed vulnerabilities are handled through our incident and vulnerability management processes.
Remediation. We fix confirmed vulnerabilities according to their severity, in line with our internal remediation timelines, and let you know when the issue has been resolved.
Disclosure. We are happy to coordinate public disclosure with you once a fix is in place.
Safe harbour
If you act in good faith and follow this policy, we will consider your research authorised. We will not pursue or support legal action against you, and we will not report you to law enforcement, for that research. If a third party brings legal action against you for activities that were conducted in accordance with this policy, we will make it known that your actions were authorised by us.
If you are unsure whether a planned activity is within this policy, ask us at security@gilion.com before you start.
Rewards
Gilion does not currently run a bug bounty programme and does not offer monetary rewards for reports. With your permission, we are glad to credit researchers who report valid vulnerabilities.
Last updated: October 5, 2026