← GridDown
Legal · GridDown

GridDown Security Policy

Last updated: June 2026 · BlackAtlas LLC

Our Commitment to Security

BlackAtlas LLC takes security seriously. GridDown is designed with a security-first mindset:


Supported Versions

We provide security updates for the following versions:

Recommendation: Always use the latest version for the best security.


Reporting a Vulnerability

How to Report

If you discover a security vulnerability in GridDown, please report it responsibly:

Email: info@blackatlas.tech

Include in your report:

  1. Description of the vulnerability
  2. Steps to reproduce
  3. Potential impact assessment
  4. Any proof-of-concept code (if applicable)
  5. Your suggested fix (optional but appreciated)

PGP Key (optional): Available at https://blackatlas.tech

What NOT to Do


Response Timeline

Severity-Based Response


Safe Harbor

We support responsible security research. If you:

We will:


Scope

In Scope

The following are within the scope of our security policy:

Out of Scope

The following are outside our security scope:


Security Architecture

Data at Rest

Data in Transit

No Data Transmitted To Us

GridDown does not transmit any data to BlackAtlas LLC servers. We have:


Known Security Considerations

Browser Storage Limitations

Third-Party API Trust

Bluetooth/Serial Connections

Offline Map Integrity

PWA Installation

Plan Sharing


Security Best Practices for Users

General

  1. Keep GridDown updated - Install new versions promptly
  2. Use HTTPS - Always access GridDown via HTTPS
  3. Secure your device - Use screen lock, encryption
  4. Regular exports - Backup important data

For Sensitive Operations

  1. Verify GPS accuracy - Cross-check critical positions
  2. Use strong passphrases - For encrypted plan exports
  3. Clear data when needed - Browser settings → Clear site data
  4. Audit permissions - Review granted device permissions

For Hardware Integrations

  1. Trust your devices - Only connect known hardware
  2. Secure your network - For AtlasRF WebSocket connections
  3. Physical security - Protect connected devices

Security Updates

Security updates are distributed through:

  1. Version updates - Install latest version
  2. Service worker - Automatic background updates
  3. Security advisories - Posted in CHANGELOG.md
  4. Critical alerts - Email to registered contacts (if opted in)

Verifying Authenticity

To verify you have an authentic GridDown release:

  1. Download only from official sources
  2. Check version number in Settings → About
  3. Verify service worker version matches release

Vulnerability Disclosure History

We will document disclosed vulnerabilities here after fixes are released.


Bug Bounty

We do not currently offer a paid bug bounty program. However, we:


Security Contact

Email: info@blackatlas.tech

Response Time: Within 48 hours

Encryption: PGP key available at https://blackatlas.tech

Alternative Contact: info@blackatlas.tech (if security@ is unresponsive)


Related Documents


Thank you for helping keep GridDown secure!


© 2025–2026 BlackAtlas LLC. All Rights Reserved.