Policy

Security Policy

How to report a vulnerability in Gianna and what to expect in return.

policysecurity

Updated 2026-06-05 · https://gianna.chat/security

Last updated: 5 June 2026

We take the security of Gianna and the data entrusted to it seriously. This document explains how to report a vulnerability and what to expect in return.

Gianna is a Catholic household assistant reached over Telegram and a web app at gianna.chat. It is proprietary software (see LICENSE); this policy concerns coordinated disclosure of security issues, not any grant of rights to the code.

Reporting a vulnerability

If you believe you have found a security vulnerability, please report it privately. Do not open a public issue, post it publicly, or share it with others before we have had a chance to address it.

Email security@gianna.chat with:

If you wish to send sensitive details, ask us in your first message and we will arrange an encrypted channel.

Our commitment

Scope

In scope:

Out of scope (please do not report or test these):

Responsible testing

When investigating, please:

We will not pursue or support legal action against researchers who act in good faith and follow this policy.

How we protect your data

Some of the measures built into Gianna:

For how we collect and handle personal data, see the Privacy Policy. For the terms governing use of the Service, see the Terms of Service.

Contact

Security reports: security@gianna.chat General enquiries: support@gianna.chat