Limited Availability
Security

Report a vulnerability

If you think you've found a security problem in Gnok, please tell us. We appreciate it.

How to report

Email security@gnok.io with:

  • what you found and where (the URL, endpoint or feature);
  • steps to reproduce it, and what an attacker could do with it;
  • how to reach you for follow-up questions.

We will acknowledge your report within 3 business days, keep you updated while we fix it, and tell you when it's resolved. Our machine-readable contact details are in /.well-known/security.txt.

In scope

  • gnok.io and docs.gnok.io
  • studio.gnok.io (Gnok Studio)
  • *.staging.gnok.io (sign-in, catalog and SQL services)
  • mail-pilot.gnok.io and mail.gnok.io
  • gnokmail.com and staging.gnokmail.com

Please

  • Test only with accounts and organizations you created yourself.
  • Never access, change or delete another organization's data. If you reach someone else's data by accident, stop, don't keep a copy, and tell us what you saw.
  • Don't run denial-of-service tests, load tests, or automated scanning that degrades the service for others. Gnok is a shared preview with limited capacity.
  • No social engineering, phishing, or physical attacks against people or offices.
  • Give us a reasonable time to fix the issue before you share it publicly; we'll agree on a date with you.

Safe harbor

If you follow this policy and act in good faith, we will consider your research authorized, we won't pursue or support legal action against you for it, and we'll work with you to understand and fix the problem. If you're unsure whether something is allowed, ask us first at security@gnok.io.

Not a security issue?

For account help, limits, or anything else, email support@gnok.io. Service health is on the status page.