Vulnerability Disclosure Policy

Giga, operated by Tonic Labs Limited, is committed to the security of our systems and our users' data. We value the work of security researchers, and this policy explains which systems are in scope, how to conduct testing safely, and how to report a vulnerability to us.

1. Guidelines

We ask that you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Give us a reasonable amount of time to resolve the issue before disclosing it publicly.
  • Make every effort to avoid privacy violations, degradation of the user experience, disruption to production systems, and the destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability. Do not use an exploit to exfiltrate data, establish persistence, or pivot to other systems.
  • If you encounter any sensitive data (personal, financial, or proprietary), stop your test, notify us immediately, and keep the data strictly confidential.
  • Do not submit a high volume of low-quality reports.

2. Authorization & Safe Harbour

Security research carried out in good faith and in accordance with this policy is considered authorised. We will work with you to understand and resolve the issue quickly, and Tonic Labs Limited will not recommend or pursue legal action in connection with your research.

3. Scope

This policy applies to the following systems and services:

  • The Giga marketing website (getgiga.com)
  • The Giga web application (app.getgiga.com)
  • Giga's integrations with Google Workspace and Slack

Any service not explicitly listed above is out of scope and must not be tested. Vulnerabilities in third-party services Giga integrates with are not covered by this policy and should be reported directly to the relevant vendor. If you are unsure whether a system is in scope, email us at security@getgiga.com before you begin.

4. Testing That Is Not Authorised

  • Network denial-of-service (DoS or DDoS) testing.
  • Physical testing (e.g. office access, tailgating), social engineering (e.g. phishing, vishing), and any other non-technical testing.

5. Reporting a Vulnerability

To report a security issue, email security@getgiga.com. Reports may be submitted anonymously. To help us triage and respond, please include where possible:

  • A description of the vulnerability.
  • Where it was discovered (URL, endpoint, or component).
  • The potential impact.
  • Steps to reproduce it (scripts and screenshots are helpful).

If possible, please provide your report in English.

6. Our Commitment

We will acknowledge receipt of your report within three business days. If you provide contact details, we will keep you informed of our progress on confirming and remediating the issue to the best of our ability, and we welcome a dialogue about your findings.

Last updated: July 2026

© 2026 Tonic Labs Limited. All rights reserved.