If you believe you have found a security vulnerability in this repository or in the GTM-Bench tooling, please report it privately to vulnerability@blackpearl.com. Please do not open a public issue or pull request for security matters.
Where possible, include:
- a description of the issue and its potential impact;
- steps to reproduce, or a proof of concept;
- any affected files, commits, or configuration;
- a name or handle if you would like acknowledgement.
This policy covers the code, configuration, and documentation in this repository. The GTM-Bench public package is a benchmark harness intended for reproduction. It does not include Blackpearl production systems, customer data, or internal credentials, and reports should not depend on accessing those.
We aim to acknowledge genuine reports within 10 business days and will keep you informed as we assess and remediate. We ask that you give us a reasonable opportunity to address an issue before any public disclosure, and that any testing avoids accessing or modifying data you do not own, degrading services, or breaching applicable law.
Blackpearl Group will not pursue action against researchers who report vulnerabilities in good faith, act in accordance with this policy, and avoid privacy violations and service disruption.