Vulnerability Disclosure Policy

Last updated: August 27, 2026

1. Overview

Fluxon LLC takes the security of GateLLM seriously. We welcome and appreciate responsible disclosure of security vulnerabilities from security researchers, customers, and community members. This policy sets out the process for reporting vulnerabilities, our response commitments, and the code of conduct for reporters acting within our authorization.

This policy aims to protect user data and system security while providing a clear, predictable collaboration framework for good-faith reporters, avoiding legal concerns arising from good-faith security research.

2. Reporting Channels

Please report security vulnerabilities via one of the following channels:

  • Preferred email: security@gatellm.io
  • PGP-encrypted communication: request our PGP public key first (included in an auto-reply), then send vulnerability details using encrypted communication. We strongly recommend PGP encryption for reports containing exploitable details.
  • Urgent vulnerabilities (actively exploited / affecting production data): mark the email subject "URGENT" for prioritized handling.

Please do not disclose unpatched vulnerability details via public channels (GitHub Issues, social media, public forums) to prevent malicious exploitation. We commit to acknowledging and fixing valid reports within a reasonable timeframe.

3. Report Contents

To help us quickly assess and reproduce, please include as much of the following as possible:

  • A clear description of the vulnerability and the affected component (e.g., GateLLM gateway process, Edge Function, admin interface)
  • Reproduction steps (as detailed as possible, with screenshots or PoC)
  • An impact assessment (what it can be used for, which data is affected)
  • Your contact information so we can provide progress updates and coordinate disclosure
  • If known, a suggested mitigation or remediation

4. Response SLA

Our response commitments for valid vulnerability reports are as follows:

  • Acknowledgement: within 24 hours (business days); urgent vulnerabilities within 4 hours
  • Initial assessment: preliminary assessment and severity rating (CVSS v3.1) within 3 business days
  • Remediation timeline: see Section 6
  • Progress updates: every 7 days during remediation, or at key milestones
  • Completion notification: after the vulnerability is fixed and verified, notify the reporter and negotiate the public disclosure timing

5. Report Scope

In-scope systems and components:

  • The GateLLM website (www.gatellm.io) and its subdomains
  • Vulnerabilities in the GateLLM software itself (gateway process, Edge Functions, authentication, billing logic)
  • Docker images and Helm Charts officially provided by GateLLM

Out of scope:

APIs or services of downstream model providers (report directly to the provider)

Deployment configuration issues of GateLLM on a customer's own infrastructure (unless attributable to a software defect)

Non-technical vulnerabilities (e.g., social engineering targeting employees, physical security)

Known low-impact issues (e.g., missing X-Frame-Options and other documented generic findings, unless they can be chained for exploitation)

Denial-of-service (DoS) testing, automated mass scanning, brute-forcing, and any behavior that may affect the availability of services for other users or production

6. Severity Rating & Remediation Timeline

We rate vulnerabilities using CVSS v3.1 and remediate them on the following timeline:

  • Critical (CVSS 9.0-10.0): fix or provide effective mitigation within 7 days; release a formal fixed version within 30 days
  • High (CVSS 7.0-8.9): fix within 30 days; release a formal fixed version within 60 days
  • Medium (CVSS 4.0-6.9): fix within 60 days; release a formal fixed version within 90 days
  • Low (CVSS 0.1-3.9): fix within 90 days, or in the next scheduled release

These are committed targets; actual timelines may adjust based on vulnerability complexity and dependency remediation progress — we will report honestly in our progress updates. Security-related fixes are annotated with CVE IDs or vulnerability summaries in the release changelog (after the coordinated disclosure window).

Incident Response & Support

7. Penetration Testing Summary

Independent third-party penetration testing of GateLLM is in preparation (scope and rules of engagement are ready). A summary will be published on this page once completed, and enterprise customers may contact security@gatellm.io to request a redacted report for procurement assessment.

8. Authorized Conduct & Prohibited Actions

When conducting good-faith security research within the scope of this policy, the following actions are considered authorized:

  • Testing your own GateLLM instance, or one you are explicitly authorized to test
  • Testing the GateLLM website (only for finding vulnerabilities within the scope of this policy, without disrupting service availability)
  • Providing sufficient detail in your report for us to reproduce and fix

Prohibited actions:

Accessing, modifying, or deleting others' data

Denial-of-service attacks, automated mass scanning, brute-forcing

Publicly disclosing details before the vulnerability is fixed

Monetizing a vulnerability or selling vulnerability information to third parties

Causing actual impact to the GateLLM production environment or user data

Violating the above prohibitions may result in legal liability and forfeiture of the good-faith cooperation protections offered by this policy. If you accidentally come into contact with others' data during testing, stop immediately, do not retain it, and report it honestly.

9. Coordinated Disclosure

We follow the Coordinated Disclosure principle:

  • The reporter and we jointly agree on the public disclosure timing (typically within 90 days after the fix is released)
  • We commit to providing a fix or mitigation within 90 days of receiving a valid report; if not fixed within the timeframe, the reporter may publicly disclose
  • Both parties may adjust the disclosure timing by mutual agreement (e.g., if dependency remediation requires more time)

10. Acknowledgments

We thank every researcher who helps us improve the security of GateLLM in a responsible manner. With the reporter's consent, we will list acknowledgments in this section (anonymity is supported). To be acknowledged, please indicate your preferred form of attribution in your report.

11. Contact

Security vulnerability reports: security@gatellm.io (request PGP public key).

Data protection inquiries: privacy@gatellm.io. General support: support@gatellm.io.

Security & Compliance · Incident Response & Support

GateLLM is a product of Fluxon LLC, a Delaware limited liability company.