Responsible Disclosure
Last updated August 6, 2026 · Groovy Milk LLC · 11101 Resort Road, #194, Ellicott City, MD 21042
We run a security practice ourselves, so we welcome good-faith reports about our own systems. This policy explains how to report and what you can expect.
How to report
Email hello@groovymilk.io with a description of the issue, the affected URL or component, reproduction steps and the potential impact. Please report in English and give us a reasonable period to remediate before any public disclosure. You may also send sensitive reports by mail to Groovy Milk LLC, 11101 Resort Road, #194, Ellicott City, MD 21042, USA.
Scope
In scope: groovymilk.io and systems we clearly own. Out of scope: client systems and any third-party service, which we are not authorized to permit testing on — contact that owner directly. Also out of scope: volumetric or denial-of-service testing, social engineering of our team or clients, physical attacks, spam, and automated scanning that degrades service.
Good-faith conditions
When you act in good faith under this policy — avoiding privacy violations, data destruction, service disruption and access to data that is not your own, and stopping as soon as you confirm a vulnerability — we will not pursue or support legal action against you for your research. Nothing in this policy authorizes activity against systems that are out of scope, and it does not waive any third party’s rights.
What we do
We acknowledge reports, typically within one business day, keep you updated on remediation, and credit you if you would like that. We do not currently operate a paid bounty program.