Security → Responsible disclosure
Responsible disclosure
If you believe you have found a security vulnerability in TunnelCrib — the Client, Agent, Relay, Bridge, or Central Server — please report it privately before any public disclosure.
How to report
- Email support@gaur.is with a clear subject line indicating a security report.
- Include affected component(s), a description of the issue, reproduction steps, and potential impact.
- Do not include real credentials, customer data, or production access details in the report itself.
What to expect
- Acknowledgement of your report.
- Ongoing communication as the issue is investigated and, where applicable, fixed.
- Credit, if desired, once a fix has shipped and public disclosure is coordinated.
Please give us reasonable time to investigate and remediate before any public disclosure. We do not currently operate a paid bug bounty program.