GRIT®

GRIT Security Disclosure Policy

How to report a security vulnerability in GRIT®, and our commitments to you if you do

DocumentSecurity Disclosure Policy (GRIT-SEC)
Version1.0
Effective dateAugust 16, 2026
Supersedes— new document, no prior version
StatusPublished and in force as of August 16, 2026. This is the current version of this document.
PublisherTeam Grit LLC, 1100 Bellevue Way NE, Ste 8A-557, Bellevue, WA 98004, U.S.A.

Capitalized terms used in this document and not defined here have the meanings given to them in the GRIT End User License Agreement (the “EULA”), Section 18 (Definitions).

1. Purpose

TEAM GRIT® welcomes reports of security vulnerabilities in GRIT® and the Services. This Policy explains what to report, how to report it, what we will do, and — importantly — the protections you have if you report in good faith.

This Policy is referenced by Section 8 of the GRIT Code of Conduct and forms part of how we apply that Section.

2. Scope

In scope

• The GRIT® game client and its anti-cheat components

• GRIT® game servers, matchmaking, and account services

• grit.gg and its subdomains, including GRIT Ledger at ledger.grit.gg and its Steam OpenID sign-in flow

• Team Grit APIs and authentication flows

Out of scope

• Systems operated by our platform providers and vendors — Valve and Steam, payment processors, cloud hosts, and third-party voice, analytics, or anti-cheat vendors. Report those to the operator concerned under their own program. Nothing in this Policy authorizes activity against them.

• Social engineering of Team Grit staff, players, or vendors

• Physical attacks against our offices or people

• Denial-of-service and volumetric load testing

• Findings from automated scanners without a demonstrated impact

• Gameplay bugs, exploits, and cheats that do not have a security impact — report those to support@grit.gg, where they are handled under the Code of Conduct rather than under this Policy

• Reports that consist only of a missing hardening header or a theoretical weakness with no demonstrated path to impact

3. How to Report

Email security@grit.gg.

A useful report includes:

1. A clear description of the vulnerability and the affected component or endpoint.

2. Steps to reproduce it, in enough detail that we can follow them.

3. Proof of concept — a script, a request, a short video, or screenshots.

4. Your assessment of the impact, and any suggested remediation.

5. Any account names or test accounts you used.

6. How you would like to be credited, if at all.

Please report in English where you can, and send one vulnerability per report.

4. Good-Faith Research — Talk to Us First

4.1 We want the report. If you have found a security vulnerability in GRIT®, tell us at security@grit.gg. We would rather hear it from you than read about it later, and we will not pursue legal action or apply enforcement penalties against someone who discovers a vulnerability in the ordinary course of playing and reports it to us in good faith.

4.2 Anything beyond that needs our permission in advance. GRIT® is a competitive game protected by anti-cheat technology, and Section 2 of the GRIT End User License Agreement prohibits reverse engineering the Game and circumventing our Anti-Cheat Technology. Those restrictions apply in full. This Policy does not waive them and is not permission to test.

If you want to carry out security research that would involve doing either of those things, write to security@grit.gg first and tell us what you propose to do. We will respond. If we agree, we will say so in writing and set out what is permitted, on what systems, and for how long — and that written agreement, and nothing else, is your authorization. We may decline, and we do not have to give a reason.

4.3 Why we work this way. Protecting the game from cheating is the point of the Anti-Cheat Technology, and a blanket permission to reverse engineer it would be relied on by the people it exists to stop. Asking first costs a legitimate researcher one email. It costs a cheat developer the excuse. We would rather answer the question than have you guess.

4.4 What we will not do to someone who asks. Writing to us to ask is not itself a breach of anything, and we will not take enforcement action against you for asking. If we say no, the answer is simply no.

4.5 What this does not cover. Nothing in this Policy authorizes activity against our platform providers or vendors — including Valve, Epic Games, or our hosting providers — and it cannot waive the rights of third parties or of law enforcement. Any permission we give under Section 4.2 covers only claims that are ours to bring, and only the systems we operate. You are expected, as always, to comply with applicable law.

5. What We Commit To

StageOur commitment
AcknowledgmentWithin 3 business days of receiving your report
Triage and initial assessmentWithin 10 business days, including whether we accept the report and our severity assessment
Progress updatesAt least every 30 days while the issue is open
Remediation targetCritical: 7 days · High: 30 days · Medium: 90 days · Low: no fixed timeframe — scheduled with our normal development work
DisclosureWe will tell you when the fix ships and coordinate timing with you
CreditWe will credit you by the name or handle you choose, unless you prefer to remain anonymous

If we need longer than ninety (90) days, we will explain why and agree a revised date with you. We will not use a request for more time as a way to delay disclosure indefinitely.

6. Rewards

Team Grit does not currently operate a paid bug bounty program. At our discretion we may offer in-Game rewards or merchandise, and we will credit you as described in Section 5. If we launch a bounty program, its terms will be published here.

7. Relationship to Other Documents

7.1 Code of Conduct. Section 8 of the GRIT Code of Conduct requires you to report bugs and not to exploit them. Where you comply with this Policy, you comply with that Section.

7.2 Not a license to cheat. Knowingly exploiting a bug for gameplay advantage, or distributing an exploit to other players, is a violation of the Code of Conduct and is not protected by this Policy — regardless of whether you also report it.

7.3 EULA. Section 2(d) of the EULA restricts reverse engineering and Section 2(e) restricts circumventing our Anti-Cheat Technology. This Policy does not waive either restriction. Two things follow, and they are the whole of it:

If you found it while playing and reported it to us in good faith, we will not treat your discovery or your report as a breach. That is Section 4.1.

If we gave you written permission under Section 4.2, activity inside the scope of that permission is not a breach. Activity outside it is.

7.4 Privacy. Information you send us in a report is handled under the Privacy Policy. If your proof of concept incidentally exposes another player's personal information, tell us and delete your copy.

8. Contact and Changes

Reports: security@grit.gg. Questions about this Policy: legal@grit.gg. We may update this Policy in accordance with Section 16 of the EULA; the version in force when you submit a report applies to that report.

End of Security Disclosure Policy.