Responsible disclosure

Report a security finding

Found something in our defense engine, web app, or infrastructure? Submit below. We acknowledge within 72 hours and operate a 90-day coordinated disclosure window. Researchers acting in good faith will not face legal action.

In scope

Out of scope

50–8000 characters. Include URLs, payloads, sample requests/responses. Hash any real PII before pasting.

Prefer email? Send directly to security@gladiuscrm.com. PGP key fingerprint posted at /security (when published).

Bounty program: planned Q4 2026. Researchers who report valid findings before the program launches will be retroactively eligible for the announced bounty tier matching their finding.