Skip to content
Gelhaus Solutions
Apps Services Security Contact
EN DE

Archived version

GAdvisory terms

How GAdvisory is licensed, what reporting a vulnerability through it means, and what running a disclosure programme on it makes you responsible for.

Version 2026-09-06 Published 6 September 2026

This is the current version. It is kept here under a fixed address so it can be cited and compared. The live document is the same text.

On this page

  1. What this covers
  2. The two ways to have it
  3. Entitlements move when the plan moves
  4. Reporting a vulnerability
  5. Running a disclosure programme
  6. Artificial intelligence
  7. Acceptable use
  8. Availability
  9. If it ends
  10. No warranty, no service level, and limited liability

What this covers

GAdvisory is a platform for coordinated vulnerability disclosure: receiving reports, coordinating with the people who can fix a problem, reserving and publishing identifiers, and publishing advisories. It can be operated as a CNA's working system and as a registry of records.

These terms cover using it. They sit alongside the general terms of service, which carry liability, governing law and everything else not specific to this product.

The two ways to have it

You run it. GAdvisory is licensed under the Elastic License 2.0, plus one additional restriction from us: commercial use requires a business licence.

That addition is stated separately because ELv2 does not contain it. ELv2's own limitations are three — you may not provide the software to others as a hosted or managed service, may not circumvent the licence-key functionality, and may not remove or alter the licensing, copyright or other notices — and it otherwise permits a company to run the software commercially for its own internal purposes. Our additional term removes that permission.

Non-commercial use on your own infrastructure is free of charge. Commercial use of any kind, including internal use inside a business, needs a business licence from us.

Some features are gated behind a licence. That is a deliberate part of the design rather than an accident of packaging, and the gating is enforced by the software.

Where you run it yourself, you operate the service. We have no access to your instance, no visibility into it, and no part in what you do with it.

We run it. Where you use a hosted instance, we operate it and the data processing agreement applies together with the GAdvisory annex to it.

gadvisory.org is currently open to public registration. It is moving to invitation only, and advisory.gplatform.org will become the public home of the hosted service. Until that move happens, treat an account on gadvisory.org as an early-access account: it is provided as it is, without a service level, and the data in it is subject to the migration.

What we commit to for that move. You will be told at least 30 days before registration closes and at least 30 days before any migration that affects your data, by email to the address on your account. Existing accounts and the advisories, reports and identifiers in them carry over; the move is a change of address and of who may register, not a reset. Where an account cannot be carried over you will be told why, with time to export first, and export remains available throughout.

Entitlements move when the plan moves

Features are granted to a scope — an organisation, a project — by assigning it a plan, or by granting a feature directly. A plan is referenced live, not copied at the moment of assignment.

That means editing a plan changes every scope assigned to it, immediately. It is how a tier can be adjusted without a morning of clicking, and it is the whole cost of that: there is no per-scope snapshot to fall back on. Every such edit is recorded in the audit log.

Retiring a plan does not withdraw it from anyone. An archived plan refuses new assignments and keeps serving the scopes already on it.

A plan assignment cascades to the scopes beneath it. A descendant carrying its own plan or its own grant overrides what it inherits.

Reporting a vulnerability

If you send a report through GAdvisory, to us or to anyone else running it:

Send what is needed to understand and reproduce the problem. Proof-of-concept code is part of a serious report and is expected; using a disclosure channel to distribute malware, or to attack the recipient, is not.

Your report is kept as it was sent. The raw inbound message is retained beside the parsed version, because a report parsed wrongly has to be readable as it was written. Where it arrives by email, the headers are kept with it.

An embargo is something you accept, not something implied. Where an advisory is under embargo, participants are named and each records their acceptance. If you are added to one, what you agreed to is not to disclose before the date.

Not accepting an embargo is not permission to publish. It means the embargo's own terms do not bind you — it does not release you from anything else. Confidentiality you already owe, a duty arising from how the material reached you, and the protection of trade secrets under the GeschG­heimG all continue to apply on their own terms, and a platform cannot and does not waive them for you. If you receive embargoed material you have not accepted an embargo over and do not wish to be bound, the thing to do is tell the coordinator and stop reading it.

Credit is optional and it is consent. If you ask to be credited, we publish the name and contact you asked for. You may withdraw that consent and we will remove the credit from our copy.

Publication is permanent. A published advisory is mirrored, indexed and aggregated into vulnerability databases with which we have no relationship. We can change our copy. We cannot change theirs. This is stated at length in the privacy notice and it is the single thing worth understanding before asking to be named.

Running a disclosure programme

If you use GAdvisory to receive reports:

The reports are yours. You decide what to act on, what to publish, whom to credit and when. We do not triage on your behalf, do not validate what you receive, and do not contact reporters for you.

You are responsible for what you publish, including for advisories naming products that are not yours. Where a record makes a claim inside a container belonging to somebody else, that party can contest it. GAdvisory records the contest and renders it as an unresolved reference rather than discarding it; it does not decide who is right. That is between you and them, and neither the software nor we adjudicate it.

Where you operate as a CNA through GAdvisory, the rules of the CVE Program apply to you in addition to these terms, and they come from the CVE Program rather than from us. Nothing here grants CNA authority, a CNA scope, or the right to assign an identifier.

Artificial intelligence

The AI features are off unless somebody turns them on, are configured per scope, and run on an API key you supply. GAdvisory ships no model provider. If you enable them, the content of a disclosure report can be sent to whichever provider that key belongs to, on that provider's terms, and each stored credential records whether that provider trains on what it is sent.

On gadvisory.org and the hosted service they are enabled for the scopes Gelhaus Solutions and Postiz own, restricted to the Gelhaus Solutions team as the people who may run them rather than restricted in what they may read. Within those scopes that reaches disclosure reports, queues and disputes. The provider is OpenRouter, routing to Google Gemini.

This does not extend to your scope. We do not run AI tasks over a customer's scope. The AI configuration for your scope is yours, the key is yours, and the provider is whichever your key belongs to. See the privacy notice and the processing annex, which say the same thing in more detail.

Acceptable use

Beyond the general terms: do not use a disclosure platform to coordinate an attack, to threaten anybody, or to extort. Do not submit reports you have no good-faith belief in to occupy somebody's queue. Do not use an embargo you have been admitted to as a source of trading advantage.

We may suspend an account that does any of these, and will say why.

Availability

No service level is promised for hosted GAdvisory unless a separate signed agreement states one. See the general terms.

If it ends

Where a hosted instance is discontinued, you may export your data, and the deletion terms in the data processing agreement apply.

Advisories already published stay published. That is what publishing them meant.

No warranty, no service level, and limited liability

This product is provided as it is and as it happens to be available, without warranty of any kind, and is used at your own risk. No uptime, response time or restoration time is owed unless a separate signed agreement states one. Where it is provided free of charge, liability is limited to intent and gross negligence (Section 521 BGB).

To the fullest extent the law permits, we are not liable for damage arising from its use, its unavailability, or any loss of data — and keeping your own backups is your responsibility. The limits that mandatory law requires, the exclusions that apply within them, and the additional cap that applies to business customers are set out in full in the general terms of service, which govern this product and are not restated here.

Version identifier

gadvisory-terms-2026-09-06

Content hash, SHA-256

7fde0e3647ef2bcfc9435d23065070f3dd8090c2eebeaed869d8272d2e4cd4cf

All documents →

Gelhaus Solutions

Self-hosted applications, and the platform that hosts them for the people who would rather not.

Site

  • Apps
  • Security
  • Writing
  • Contact
  • Sitemap

GHub

  • GAnalytics
  • contribution-checker
  • GAdvisory
  • GeGroups
  • GControl

Legal

  • Impressum
  • Privacy
  • Terms
  • Data processing
  • Withdrawal
  • Report content

Elsewhere

  • egelhaus@ennogelhaus.de
  • @egelhaus
  • @egelhaus
© 2026 Enno Gelhaus Built and shipped in Germany