Legal
Security and Responsible Disclosure
CostGrid's current security boundaries and safe vulnerability-reporting expectations.
Draft — not yet effective · Version 0.1.0
Draft pending production verification and a dedicated disclosure contact route.
Current controls
CostGrid is designed around authenticated identities, organisation and project membership, database row-level controls, protected server functions, fixed-precision financial records, governed approvals, restricted storage paths and attributable audit events. Exact production evidence is tracked in protected Mission Control.
Responsible disclosure
Do not access another customer's data, disrupt service, use automated high-volume testing, exfiltrate content or retain unnecessary personal information. Report the affected route or component, time observed and safe reproduction details through the verified security contact once published. Raw secrets and complete exploit payloads must not be placed in public tickets.
No unsupported assurance
No certification, penetration-test outcome, encryption standard, data-residency guarantee, uptime commitment or universal security guarantee is claimed without current evidence for the exact release.
Change history
Version 0.1.0: initial governed draft. It is not effective and cannot be accepted as a published version.