How to report

Email hello@gourhit.com with Security in the subject line. There is no bug bounty; there is a person who reads it.

  • What you found, and which site or product it affects.
  • The steps to reproduce it, in enough detail that we can.
  • What an attacker could do with it.
  • How you would like to be credited, if you would like to be.

Scope

This site, and the products the company owns and operates:

  • gourhit.com
  • laenso.com

Software the company built under contract belongs to the client who commissioned it, and reports about it should go to them. If you are not sure who that is, write to us and we will pass it on.

What we ask

Give us a reasonable opportunity to fix the problem before you publish it. Do not access, modify or delete data that is not yours, do not degrade a service for its users, and do not use social engineering or physical access against anyone.

Automated scanning at a volume that affects availability is a denial-of-service test, not a vulnerability report, and we will treat it as one.

In return: we will acknowledge your report, tell you what we found when we have looked at it, and let you know when it is fixed. We will not pursue action against research carried out in good faith and within the terms on this page.