GRIDer

Security and Coordinated Vulnerability Disclosure

Version 2026-09-26

We want to know as soon as possible if you find a security problem in GRIDer Pack or on our servers. This page explains how to tell us, what we commit to and how we publish security advisories.

How to report a vulnerability

Write to us at info@grider.xyz. If you can, include:

  • the affected component: the software version (shown in the application), the installer, the updater, or the affected server or site (grider.xyz, docs, get, registry or scanner);
  • a description of the problem and its impact;
  • the steps to reproduce it and, if you have one, a proof of concept;
  • whether you know or suspect that it is being exploited;
  • how to contact you and whether you want to be credited when we publish the advisory.

Do not include other people's personal data or real keys or seed phrases. Our contact is also in security.txt.

What we commit to

  • We acknowledge receipt within 72 hours at most.
  • We assess the problem, keep you informed of progress and let you know when it is fixed.
  • We agree with you when to publish the details: generally, once the fix is available and users have had reasonable time to install it.
  • If you wish, we credit your contribution in the advisory.

Good-faith research: authorisation and safe harbour

We authorise you to research the security of what is in scope of this policy —your own installation of GRIDer Pack and our servers listed under "Scope"— as long as you follow these rules:

  • test only with your own accounts, licences and installations; do not access, modify, delete or keep other people's data; if you come across someone else's data, stop, do not keep it and tell us;
  • do not run denial-of-service attacks or tests that degrade, interrupt or damage our servers or anyone else's;
  • do not use social engineering, phishing or physical attacks against anyone;
  • do not exploit the vulnerability beyond what is needed to demonstrate it, do not use it for your own benefit and do not leave persistent access or changes;
  • do not disclose it before we have fixed it or before the date we agree with you.

If you follow these rules:

  • we consider your research authorised by us as regards our systems;
  • we will not file a criminal complaint against you for it, we will not bring civil claims and we will not enforce the restrictions in our licence terms (for example, on reverse engineering) to the extent needed for that research; if proceedings that depend on our complaint had been started, we will grant our pardon where the law allows;
  • if a third party takes action against you over research that complied with this policy, we will make it known that it was authorised by us.

What we cannot promise. This commitment only covers what is within our control:

  • we cannot authorise testing of systems that are not ours: other customers' installations, the exchanges, server, DNS or certificate providers, or any other third-party service. Report to their owners under their own policies;
  • we cannot waive claims of other affected people, such as the owners of personal data;
  • we cannot prevent prosecutors or courts from acting where the law allows them to do so without our complaint — for example, computer damage or system interference (Articles 264 and 264 bis of the Spanish Criminal Code), or conduct affecting general interests or a plurality of persons (Article 201(2));
  • we will keep meeting our legal obligations: notifying a personal data breach to the data protection authority, notifying INCIBE-CERT and ENISA of a vulnerability where there is evidence that a malicious actor has exploited it, and complying with requests from courts and authorities.

If you are unsure whether something is allowed, ask us first at info@grider.xyz.

Scope

  • In scope: your own installation of GRIDer Pack (on your server or computer); GRIDer Pack (software image, installer and updater) and the seller's servers: grider.xyz, docs.grider.xyz, get.grider.xyz, registry.grider.xyz and scanner.grider.xyz.
  • Out of scope: other customers' installations and the configuration of servers that are not yours; the exchanges and other third-party services; denial-of-service and social-engineering tests.

Supported versions

During each license we support and publish security updates for the current version and the one immediately before it. Each customer applies the updates on their own installation; the installed version is shown in the application.

How we publish security advisories

  • On this page (list below), also in machine-readable form at /security/advisories.json.
  • With a notice inside the application.
  • On your installation's Telegram, if you have configured it.
  • When necessary, by email to affected customers.

Notification to the authorities

As manufacturer of the software, we notify actively exploited vulnerabilities and severe incidents affecting GRIDer Pack to the CSIRT designated as coordinator —in Spain, INCIBE-CERT— and to ENISA, through the single reporting platform, under Article 14 of Regulation (EU) 2024/2847 (Cyber Resilience Act), and we inform the affected users.

Your data

We process the details of people who report vulnerabilities as explained in the Privacy Policy.

Published advisories

No advisories published.

GRIDer

Self-hosted grid trading software. Your environment, your control.

GRIDer is software you install and operate yourself, on your own account and with your own funds. It is not an investment service, it does not manage anyone else’s money, and nothing on this site is investment advice or a recommendation to trade. Trading crypto derivatives involves leverage and a high risk of loss.

Exchange names and logos that appear on this site, such as Hyperliquid, Lighter, Pacifica, Extended, RISEx or Aster, are trademarks of their respective owners. GRIDer is independent software, not affiliated with, sponsored or endorsed by any of them; they are used only to indicate compatibility.

© 2026 GRIDer. Decentralized trading.

grider.xyz