Grej — Coordinated Vulnerability Disclosure
Early Access · Effective 17 August 2026
Grej is operated by Humeko Oy (see the Privacy Policy for company details). We take the security of our users' data seriously and we welcome reports of potential security vulnerabilities in Grej. This page is our coordinated vulnerability disclosure policy: what is in scope, how to report an issue, and how we handle reports. Security contact: security@grej.app.
What's in scope
- The Grej iOS app as distributed on the Apple App Store.
- The Grej backend the app relies on (
api.grej.app), without which the app cannot work. - Third-party components we ship inside the above — for example an open-source library or SDK bundled into the app or the backend.
Out of scope:
- Separately-operated third-party services and infrastructure we build on — Google Cloud, Apple (App Store, Sign in with Apple), Expo, Sentry. Please report a flaw in their own service through their disclosure programmes. (A vulnerable component we ship inside Grej is in scope above — please do report that to us.)
- Findings that require a compromised device, a rooted/jailbroken OS, or a malicious app already present on the phone.
- Reports that don't show a real security impact: missing security headers with no demonstrated impact; SPF/DKIM/DMARC opinions; rate-limiting or "best-practice" suggestions without a concrete exploit; self-XSS; clickjacking on pages with no sensitive action; output from an automated scanner with no verified impact; and social-engineering, phishing, or physical attacks against our staff or users.
If you're not sure whether something is in scope, just ask us at security@grej.app.
What we ask of you
We're grateful to anyone who takes the time to look for and report security issues in Grej. This policy grants no authorisation to test beyond what the law already permits, and we're in no position to impose rules on you — but to keep our users safe, we'd be grateful if you would:
- Please test only with your own account and your own data — and avoid accessing, changing, or deleting anything that belongs to someone else.
- Please keep any impact to a minimum — stop once you've confirmed an issue, look at only what you need to demonstrate it, and please don't download, keep, or copy user data.
- Please take special care with personal data. If you come across personal data that isn't yours, we'd be grateful if you'd stop, not view or keep it, and let us know — a quiet heads-up genuinely helps.
- Please avoid disrupting the service — for example denial-of-service, load or stress testing, high-volume automated scanning against production, or spamming forms or users.
- Please don't use social engineering, phishing, or physical intrusion against our staff, our users, or our facilities.
- Please give us a reasonable chance to fix an issue before disclosing it publicly (see below).
- Please stay within the law — nothing here authorises activity that would be unlawful under Finnish, Swedish, or EU law.
Thank you — following these keeps testing safe for our users, and we appreciate it.
How to report
Send your report to security@grej.app. You're welcome to report anonymously, though it makes it harder for us to follow up with you.
Please include:
- A clear description of the vulnerability and the product, URL, or endpoint affected.
- Steps to reproduce — a proof of concept, request/response samples, or a short video.
- The impact you believe it has (what an attacker could do).
- Any prerequisites (account type, configuration, tooling).
You do not need to have a fix. One clear report per issue is easier for us to act on than a batch.
How we handle reports
We review the reports we receive for the in-scope products. Where a report is valid, we remediate the vulnerability without undue delay, provide a security update, and publish information about the fixed vulnerability once an update is available. We treat reports confidentially. We do not commit to specific response, assessment, or resolution timeframes.
Coordinated disclosure
Following coordinated vulnerability disclosure practice, public disclosure should come after a fix or mitigation is available. We'd be grateful if you would give us a reasonable period to remediate before disclosing publicly — please hold off on publishing details, sharing proof-of-concept exploits, or telling third parties in the meantime — and we'll gladly coordinate the timing with you.
If we are unresponsive, or you would simply prefer a neutral coordinator, you're welcome to involve your national CSIRT (in Finland, NCSC-FI / Traficom; in Sweden, CERT-SE), which can act as a coordinator.
Legal & privacy
This policy grants no rights over Grej's or any third party's systems, and no authorisation to test beyond what the law already permits. That said, we assume anyone who reports a vulnerability in good faith and within the law is trying to help, and we will engage with you in that spirit. This is not a waiver of any legal right and does not extend to unlawful activity. Please handle any personal data you come across as described above, and don't retain it. Grej does not operate a bug-bounty programme and does not offer rewards for reports. This policy is governed by Finnish law and does not limit the mandatory rights of consumers or data subjects. Questions about this policy: security@grej.app.