Security contact
Report a vulnerability
Email security@gnok.io with what you found, where, and how to reproduce it. We acknowledge reports within 3 business days.
Our vulnerability disclosure policy explains what's in scope, what testing is allowed, and our safe harbor for good-faith research. The machine-readable contact is at gnok.io/.well-known/security.txt.
Please:
- test only with organizations and accounts you created;
- never access or keep another organization's data;
- don't run load, denial-of-service, or aggressive automated scans: Gnok is a shared preview with limited capacity.
Report a compromised account
If you think someone else has signed in to your account or organization:
- Change your password and review your passkeys and authenticator app in Studio (see Account access).
- If you're an administrator, review members, sessions and API access for your organization.
- Email security@gnok.io with your organization's sign-in name and what you noticed.
Everything else
For help that isn't about security, email support@gnok.io. Service health is on the status page.