GRIT®
GRIT Security Disclosure Policy
How to report a security vulnerability in GRIT®, and our commitments to you if you do
| Document | Security Disclosure Policy (GRIT-SEC) |
|---|---|
| Version | 1.0 |
| Effective date | August 16, 2026 |
| Supersedes | — new document, no prior version |
| Status | Published and in force as of August 16, 2026. This is the current version of this document. |
| Publisher | Team Grit LLC, 1100 Bellevue Way NE, Ste 8A-557, Bellevue, WA 98004, U.S.A. |
Capitalized terms used in this document and not defined here have the meanings given to them in the GRIT End User License Agreement (the “EULA”), Section 18 (Definitions).
1. Purpose
TEAM GRIT® welcomes reports of security vulnerabilities in GRIT® and the Services. This Policy explains what to report, how to report it, what we will do, and — importantly — the protections you have if you report in good faith.
This Policy is referenced by Section 8 of the GRIT Code of Conduct and forms part of how we apply that Section.
2. Scope
In scope
• The GRIT® game client and its anti-cheat components
• GRIT® game servers, matchmaking, and account services
• grit.gg and its subdomains, including GRIT Ledger at ledger.grit.gg and its Steam OpenID sign-in flow
• Team Grit APIs and authentication flows
Out of scope
• Systems operated by our platform providers and vendors — Valve and Steam, payment processors, cloud hosts, and third-party voice, analytics, or anti-cheat vendors. Report those to the operator concerned under their own program. Nothing in this Policy authorizes activity against them.
• Social engineering of Team Grit staff, players, or vendors
• Physical attacks against our offices or people
• Denial-of-service and volumetric load testing
• Findings from automated scanners without a demonstrated impact
• Gameplay bugs, exploits, and cheats that do not have a security impact — report those to support@grit.gg, where they are handled under the Code of Conduct rather than under this Policy
• Reports that consist only of a missing hardening header or a theoretical weakness with no demonstrated path to impact
3. How to Report
Email security@grit.gg.
A useful report includes:
1. A clear description of the vulnerability and the affected component or endpoint.
2. Steps to reproduce it, in enough detail that we can follow them.
3. Proof of concept — a script, a request, a short video, or screenshots.
4. Your assessment of the impact, and any suggested remediation.
5. Any account names or test accounts you used.
6. How you would like to be credited, if at all.
Please report in English where you can, and send one vulnerability per report.
4. Good-Faith Research — Talk to Us First
4.1 We want the report. If you have found a security vulnerability in GRIT®, tell us at security@grit.gg. We would rather hear it from you than read about it later, and we will not pursue legal action or apply enforcement penalties against someone who discovers a vulnerability in the ordinary course of playing and reports it to us in good faith.
4.2 Anything beyond that needs our permission in advance. GRIT® is a competitive game protected by anti-cheat technology, and Section 2 of the GRIT End User License Agreement prohibits reverse engineering the Game and circumventing our Anti-Cheat Technology. Those restrictions apply in full. This Policy does not waive them and is not permission to test.
If you want to carry out security research that would involve doing either of those things, write to security@grit.gg first and tell us what you propose to do. We will respond. If we agree, we will say so in writing and set out what is permitted, on what systems, and for how long — and that written agreement, and nothing else, is your authorization. We may decline, and we do not have to give a reason.
4.3 Why we work this way. Protecting the game from cheating is the point of the Anti-Cheat Technology, and a blanket permission to reverse engineer it would be relied on by the people it exists to stop. Asking first costs a legitimate researcher one email. It costs a cheat developer the excuse. We would rather answer the question than have you guess.
4.4 What we will not do to someone who asks. Writing to us to ask is not itself a breach of anything, and we will not take enforcement action against you for asking. If we say no, the answer is simply no.
4.5 What this does not cover. Nothing in this Policy authorizes activity against our platform providers or vendors — including Valve, Epic Games, or our hosting providers — and it cannot waive the rights of third parties or of law enforcement. Any permission we give under Section 4.2 covers only claims that are ours to bring, and only the systems we operate. You are expected, as always, to comply with applicable law.
5. What We Commit To
| Stage | Our commitment |
|---|---|
| Acknowledgment | Within 3 business days of receiving your report |
| Triage and initial assessment | Within 10 business days, including whether we accept the report and our severity assessment |
| Progress updates | At least every 30 days while the issue is open |
| Remediation target | Critical: 7 days · High: 30 days · Medium: 90 days · Low: no fixed timeframe — scheduled with our normal development work |
| Disclosure | We will tell you when the fix ships and coordinate timing with you |
| Credit | We will credit you by the name or handle you choose, unless you prefer to remain anonymous |
If we need longer than ninety (90) days, we will explain why and agree a revised date with you. We will not use a request for more time as a way to delay disclosure indefinitely.
6. Rewards
Team Grit does not currently operate a paid bug bounty program. At our discretion we may offer in-Game rewards or merchandise, and we will credit you as described in Section 5. If we launch a bounty program, its terms will be published here.
7. Relationship to Other Documents
7.1 Code of Conduct. Section 8 of the GRIT Code of Conduct requires you to report bugs and not to exploit them. Where you comply with this Policy, you comply with that Section.
7.2 Not a license to cheat. Knowingly exploiting a bug for gameplay advantage, or distributing an exploit to other players, is a violation of the Code of Conduct and is not protected by this Policy — regardless of whether you also report it.
7.3 EULA. Section 2(d) of the EULA restricts reverse engineering and Section 2(e) restricts circumventing our Anti-Cheat Technology. This Policy does not waive either restriction. Two things follow, and they are the whole of it:
• If you found it while playing and reported it to us in good faith, we will not treat your discovery or your report as a breach. That is Section 4.1.
• If we gave you written permission under Section 4.2, activity inside the scope of that permission is not a breach. Activity outside it is.
7.4 Privacy. Information you send us in a report is handled under the Privacy Policy. If your proof of concept incidentally exposes another player's personal information, tell us and delete your copy.
8. Contact and Changes
Reports: security@grit.gg. Questions about this Policy: legal@grit.gg. We may update this Policy in accordance with Section 16 of the EULA; the version in force when you submit a report applies to that report.
End of Security Disclosure Policy.