• Why Grata

    Why Grata

    Solutions

    Turn market signals into actionable deal lists

    Data

    Explore private market data with confidence

    Technology

    Build scalable systems on top of trusted data

    Why Grata

    Solutions
    SOLUTIONS
    Private Equity

    Business development and market mapping

    Investment Banking

    Deal origination and buyer list building

    Corporate Development

    Targeted market research for acquisitions

    Consulting

    Identify actionable opportunities

    Private Credit

    Next-generation market intelligence

    Data
    DATA
    Our Data

    Access verified private-market company data

    Data Quality

    Reliable data you can act on

    Technology
    TECHNOLOGY
    AI

    AI for Private Markets

    Search Engine

    AI-Powered Search

    Security

    Keep Your Data Safe

    Integrations

    Unified Data Connections

    FEATURED SPOTLIGHT

    Identify Companies Preparing to Sell Months Before the Rest of the Market

    Read more →

    Grata Expands Global Intelligence Platform with Integrated Valu8 Data, MCP Launch, and Customers in 26 Countries

    Read More →

    Supercharge Your Spreadsheets by Connecting Grata's Excel Add-In to the Grata MCP

    Read More →

  • Platform
    PLATFORM

    Source & Discover

    Find companies and opportunities

    Source & Discover

    Find companies and opportunities

    Research & Analyze

    Evaluate markets and deals

    Research & Analyze

    Evaluate markets and deals

    Connect & Automate

    Streamline workflows and execution

    Source & Discover
    SOURCE & DISCOVER
    Deal Sourcing

    Uncover new targets

    Seller Intent

    Engage warm leads first

    Buyer List Building

    Find tailored exit opportunities

    Conferences and Events

    Plan your travel schedule

    Live Deals

    Browse actionable mandates

    Pipeline Management

    Operationalize your funnel

    Research & Analyze
    RESEARCH & ANALYZE
    Deal Data

    Benchmark deals with confidence

    Industry Research

    Map markets comprehensively

    Public Comps

    Compare multiples quickly

    Excel Add-In

    Streamline financial modeling

    Market Fragmentation

    Identify unsaturated markets

    Connect & Automate
    CONNECT & AUTOMATE
    MCP

    Connect to your LLM

    API

    Build custom systems

    Data Warehouse

    Ingest Grata’s dataset

    CRM Intelligence

    Harness your relationship data

  • Pricing
  • Resources

    Resources Center

    Product

    Updates on the Grata platform and the latest tech

    Learning

    Guides for M&A professionals of all levels

    Insights

    The latest industry trends

    Media

    Webinars, videos, and more

    Resources Center

    Product
    PRODUCT
    Product

    Core tools for sourcing, tracking, and outreach

    Help Center

    Support docs and FAQs

    Learning
    LEARNING
    Learning Hub

    Educational content for M&A professionals

    Grata Scholars

    Academic programs and access

    Insights
    INSIGHTS
    Insights

    Turn raw data into actionable insight

    Case Studies

    Real-world deal examples

    Media
    MEDIA
    Media Hub

    On-demand content from Grata

    Webinars

    Live and on-demand expert sessions

    FEATURED SPOTLIGHT

    What Are MCP Servers and Why Do They Matter for Dealmakers?

    Read More →

    How to Build an AI-Native Deal Sourcing Engine

    Read More →

    How Dealmakers Win Now That AI Is Table Stakes

    Read More →

    What a Complete Market Map Actually Requires

    Read More →

    The PE Playbook: HVAC

    Read More →

    The Hidden Gems Report: Finding Low-Profile Companies in High-Momentum Industries

    Read More →

    Effective Strategies for Communicating with Limited Partners (LPs)

    Read More →

    (Webinar) Best Kept
    Sourcing Secrets

    Read More →

  • Company
    COMPANY
    About Us

    A bit about who we are

    Partners

    Why partner with Grata?

    Careers

    Explore working at Grata

    Scholars

    Your connection to a career in M&A

    Referrals

    Spread the word, and get rewarded

    FEATURED SPOTLIGHT

    Grata Expands Global Intelligence Platform with Integrated Valu8 Data, MCP Launch, and Customers in 26 Countries

    Read More →

    Introducing the
    Grata MCP Server

    Know More →

Get Started
ri arrow line
Log In
Americas
EMEA
APAC

Select the region your company operates in.

Get Started
ri arrow line

Vulnerability Disclosure Policy

Introduction

Grata Inc., the cloud-based SaaS platform, is committed to securing our products, services, and maintaining the trust of our customers. This policy prescribes how security researchers must conduct vulnerability discovery activities and submit discovered those vulnerabilities responsibly to Grata Inc. With our SaaS based platform, no patching is required to apply remediations to vulnerabilities, thus we will work directly with the researchers to confirm and validate that fixes have been applied and no longer exist. For our mobile applications, we will publicly mention any security fix in the application release notes.

You Should:

  • Respect the rules. Operate within the rules set forth herein or speak up if you strongly disagree with them.
  • Respect privacy. Do not access or destroy another userʼs data.
  • Be patient. Make a good faith effort to clarify and support your reports upon request.
  • Do no harm. Act prudently and for the common good. Promptly report of all found vulnerabilities. Never willfully exploit others without their permission.

We encourage you to contact us to report potential vulnerabilities in our systems. Thank you in advance for your submission and discretion, we appreciate researchers assisting us in our security efforts.

Authorization

In consideration for complying with this policy, Grata Inc. authorizes you to conduct security research. We will work with you to understand and resolve the issue quickly and will not recommend or pursue legal action related to your research nor support any third-party legal action brought against, unless required by law, for activities that were conducted in accordance with this policy.

Guidelines

Under this policy, “research” means activities in which you:

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent strictly necessary to confirm a vulnerability's presence. Do not use an exploit to compromise or exfiltrate data, establish persistent command line access, or use the exploit to pivot to other systems.
  • Do not submit a high volume of low-quality findings.
  • Use only the Official Channels to communicate vulnerability information with us.
  • You attest you are not a resident of, or will not make your Submission from, a embargoed country or region of the United States or that you are not, nor do you represent a legal entity, that is currently under U.S. sanction (e.g., Cuba, Iran, North Korea, Sudan, Syria and Crimea);

Once youʼve established that a vulnerability exists or encounter any sensitive data (including personally identifiable information, financial information, or proprietary information or trade secrets of any party), you must cease your test, notify us immediately, and not disclose this data to anyone else.

You agree that you will keep information related to the vulnerability confidential and will not disclose the vulnerability to any third-party unless Grata Inc. has provided you with written authorization to do so even if you decide not to report it. By submitting your vulnerability, you hereby grant Grata Inc. the right to use, create derivatives of, disclose, or modify any information that you have provided.

Scope

This policy applies to the following systems and services:

  • https://grata.com , and the following hostnames:
    • https://search.grata.com
    • Any other subdomain of https://grata.com and all customer applications are excluded from this policy.
  • Mobile applications for iOS and Android

Any service not expressly listed above, such as any connected services, are excluded from scope and are not authorized for testing. Additionally, vulnerabilities found in systems from our vendors fall outside of this policyʼs scope and should be reported directly to the vendor according to their disclosure policy (if any). If you arenʼt sure whether a system is in scope or not, contact us using the form below before starting your research.

While we encourage you to discover and report to us any vulnerabilities you find in a responsible manner, the following conduct is expressly prohibited:

  • Performing actions that may negatively impact Grata Inc. or its users (e.g. Spam, Brute Force, Denial of Service…) or other tests that impair access to or damage a system or data.
  • Accessing, or attempting to access, data or information that does not belong to you.
  • Destroying or corrupting, or attempting to destroy or corrupt, data or information that does not belong to you.
  • Physical testing (e.g. office access, open doors, tailgating), social engineering (e.g. phishing, vishing), or any other non-technical vulnerability testing.
  • Social engineering any Grata Inc. service desk, employee, or contractor.
  • Violating any laws or breaching any agreements in order to discover vulnerabilities.

Out-of-Scope Vulnerabilities:

  • Username / Email Enumeration
  • Concurrent User Sessions
  • Brute Force Attacks
  • Denial of Service Attacks
  • Missing cookie flags
  • Missing security headers
  • CORS misconfiguration against functionality without security impact
  • Cross-site Request Forgery against non-sensitive functionality
  • Presence of autocomplete attribute on web forms
  • Reverse Tabnabbing
  • Clickjacking without proven impact/unrealistic user interaction
  • HTTP Request smuggling without security impact
  • Banner grabbing/Version disclosure
  • Verbose messages/files/directory listings without disclosing any sensitive information
  • Third-party library vulnerabilities with no impact to Grata Inc. Applications
  • Automated Scanner Reports
  • Weak Cipher without Exploitability

Reporting a Vulnerability

Information submitted under this policy will be used for defensive purposes only – to mitigate or remediate vulnerabilities. We will not share your name or contact information without your express permission.

Submitting your vulnerability constitutes acceptance of this Vulnerability Disclosure Policy. Therefore, first, you should review this Vulnerability Disclosure Policy. Then submit the vulnerability using the Official Communication Channels. If you share contact information, we will acknowledge receipt of your report within 3 business days.

Upon receipt of the report, we will review and investigate the vulnerability without undue delay. We shall make every effort to notify you when this investigation starts. We use CVSS 3.0 (Common Vulnerability Scoring Standard) to calculate severity. If we determine that vulnerability requires remediation, we will start remediating the vulnerability as soon as practicable.

Official Communication Channels

Vulnerability reports should be submitted by contacting our team at security-alert@grata.com.

We do not support PGP-encrypted emails. For particularly sensitive information, reach out directly via the email address provided and ask for a meeting to be setup to discuss.

What we would like to see from you

In order to help us triage and prioritize submissions, we recommend that your reports:

  • Describe the location in which the vulnerability was discovered and the potential impact of exploitation.
  • Offer a detailed description of the steps needed to reproduce the vulnerability.
  • It is recommended to include a video or screenshot as Proof-of-Concept in your submissions. These files should not be shared publicly. This includes uploading to any publicly accessible websites (e.g. YouTube, Imgur). If the file exceeds 100MB, upload the file to a secure online service, such as Vimeo, with a password and please provide the link and password via separate delivery.
  • Well written reports in English will have a higher chance of being accepted.
  • Reports that include proof of concept code will be more likely to be accepted.
  • Reports that include only crash dumps or other automated tools output will most likely not be accepted.
  • Reports that are outside the scope of the listed will most likely be ignored.

What can you expect from us

When you choose to share your contact information with us, we shall make every effort to coordinate with you quickly and openly.

  • Extend Safe Harbor (see below) for your vulnerability research that complies with this policy.
  • Within 3 business days, we will acknowledge that your report has been received, assuming proper contact information has been included.
  • To the best of our ability, we will confirm the existence of the vulnerability to you and be as transparent as possible about what steps we are taking during the remediation process, including on issues or challenges that may delay resolution.
  • We will maintain an open dialogue to discuss issues.
  • Grata Inc. does not operate a public bug bounty program Safe Harbor

When conducting vulnerability research in compliance this policy and applicable laws, we consider this research to be:

  • Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy.
  • Exempt from the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls.
  • Exempt from restrictions in our Terms of Use that would interfere with conducting security research, and we waive those restrictions on a limited basis for work done under this policy.
  • Lawful, helpful to the overall security of the Internet, and conducted in good faith.

If at any time you have questions or concerns or you are uncertain whether your security research is consistent with this policy, please submit a report through our Official Channels before going any further.

logo white
Subscribe to Our Weekly Newsletter
Stay up to date with Grata’s latest product updates, content, events, and more.
HEADQUARTERS
New York - Headquarters
3 Columbus Circle
Floor 4
New York, NY 10019
London
15 Bonhill Street
London EC2A 4DN
England
Paris
Morning Laborde
2 Rue De Laborde, 3rd Floor
75008 Paris
Frankfurt
Vista, 1st Floor
Mainzer Landstraße 36
60325 Frankfurt am Main
San Francisco
550 California Street
Suite 720
San Francisco, CA 94104
Sydney
Level 22, Sydney Place
180 George Street
Sydney 2000 NSW, Australia
Contact Us
Sales Inquiries: inquiries@grata.com
Clients: support@grata.com
General Inquiries: hello@grata.com
LinkedIn icon

LinkedIn

WHY GRATA
SOLUTIONS
  • Private Equity
  • Investment Banking
  • Corporate Development
  • Consulting
  • Private Credit
DATA
  • Our Data
  • Data Quality
TECHNOLOGY
  • AI
  • Agentic Search
  • Security
  • Integrations
COMPANY
  • About Us
  • Careers
  • Referrals
  • Partners
  • Scholars
PLATFORM
SOURCE & DISCOVER
  • Deal Sourcing
  • Seller Intent
  • Buyer List Building
  • Conferences and Events
  • Live Deals
  • Pipeline Management
RESEARCH & ANALYZE
  • Deal Data
  • Public Comps
  • Market Fragmentation
  • Industry Research
  • Excel Add-In
CONNECT & AUTOMATE
  • MCP
  • API
  • Data Warehouse
  • CRM Intelligence
COMPARE
  • Grata vs PitchBook
  • Grata vs ZoomInfo
  • Grata vs Harmonic
  • Grata vs Inven
a blue circle with white textSOC for Service Organizations
Get the app
Apple App StoreGoogle Play Store
  • PLATFORM
  • Log in
  • Privacy Policy
  • Terms of Service
  • Do Not Sell My Info
© 2026 Grata Inc. All Rights Reserved.