We take security seriously. Thank you for helping keep Trace and its users safe.
Do not report security issues through public GitHub issues.
Email security@graycode.ai with:
- Clear description of the vulnerability
- Impact assessment
- Steps to reproduce
- Affected versions (if known)
- Suggested fix (optional)
| Stage | Timeframe |
|---|---|
| Acknowledgment | Within 48 hours |
| Status update | Within 7 days |
| Resolution target | Within 90 days for critical issues |
All reports are kept confidential.
In scope:
- The Trace CLI (
tracebinary) - Official GrayCode AI repositories
- Trace services at graycode.ai
Out of scope:
- Third-party dependency issues (report upstream)
- Social engineering
- Denial of service attacks
- Issues requiring physical device access
Advisories are issued for vulnerabilities exploitable by remote or non-local actors.
Local-only issues (ReDoS in local execution, resource exhaustion requiring local access) are treated as bug reports — use GitHub Issues.
Thank you for responsible disclosure.