Legal protection
Safe Harbor Policy
Defend.gl protects security researchers who report vulnerabilities in good faith. We will not take legal action against you as long as you follow our guidelines and act responsibly.
Last updated: August 2026
This is a convenience translation; the Danish version is legally binding.
What is Safe Harbor?
Safe Harbor is our promise to you as a security researcher: if you discover a vulnerability and report it to us responsibly, we will protect you legally.
This policy ensures that ethical hackers can test systems without fear of prosecution. It builds trust between organisations and the security community — and makes Greenland's digital infrastructure more secure.
As long as your research is carried out in good faith and follows our guidelines, Defend.gl and our partners will not:
- Initiate legal action against you
- Contact law enforcement authorities
- Report you for unauthorised access
Our commitment
Defend.gl is committed to protecting security researchers who act in good faith. We believe that collaboration — not confrontation — is the path to better cybersecurity.
This policy applies to:
- Defend.gl's platforms and systems
- Companies with active bug bounty programmes with us
- Organisations covered by the Community Fund
What is covered by Safe Harbor
The following security research activities are protected under our Safe Harbor policy:
- Vulnerability testing: Testing systems within approved scopes to identify security weaknesses, as long as you follow our guidelines.
- Responsible reporting: Reporting discovered vulnerabilities through Defend.gl's platform with detailed descriptions and proof of concept.
- Good-faith research: Security research carried out with the aim of improving security, not to harm or exploit systems.
- Private disclosure: Giving companies reasonable time to fix vulnerabilities before publication (typically 90 days).
Follow these rules to stay protected
To be covered by our Safe Harbor policy, your research must comply with the following guidelines. These rules ensure that your activity remains ethical and lawful.
- Only test approved systems: Only carry out tests on systems explicitly included in a bug bounty programme's scope. Respect out-of-scope designations.
- Respect privacy: Avoid accessing, viewing, or modifying other users' data. Only use test accounts you have created yourself.
- Preserve system integrity: Do not destroy, alter, or delete data. Keep your impact on systems and their users to a minimum.
- No service disruption: Do not carry out denial-of-service (DoS) attacks, automated scans that overload systems, or other activities that affect availability.
- Report privately first: Report vulnerabilities directly to the organisation through Defend.gl's platform. Do not publish vulnerabilities until they have been fixed and coordinated.
- Allow reasonable response time: Allow the organisation at least 90 days to address the vulnerability before considering disclosure.
- Act in good faith: Carry out research with the intention of improving security, not for personal gain, extortion, or malicious purposes.
Important note
If you inadvertently breach these guidelines during your research, contact us immediately. Openness and prompt communication help us resolve the situation and maintain your protection under Safe Harbor.
Proof of Concept
Your PoC scripts and demonstration data should be minimal and only demonstrate the vulnerability. Example: show that you can read /etc/passwd, but do not extract the entire file or other sensitive data.
Activities NOT covered by Safe Harbor
The following actions are not protected and may result in legal action:
- Social engineering: Phishing, vishing, or other social-manipulation techniques directed at employees or users.
- Physical attacks: Physical access to facilities, servers, or network equipment without explicit permission.
- Data extraction: Downloading or exfiltrating data beyond what is necessary to demonstrate the vulnerability.
- Denial of Service: DoS, DDoS, or other attacks designed to make services unavailable.
- Extortion: Demands for payment, threats of publication, or other forms of extortion.
- Public disclosure: Publishing vulnerabilities before the coordinated disclosure timeline or without the company's consent.
Our Safe Harbor commitment
Defend.gl is committed to not initiating legal action against security researchers who act in good faith and in accordance with this Safe Harbor policy.
This includes, but is not limited to, claims of unauthorised access, breach of computer security, or violation of terms of use, provided the activities stay within the guidelines set out here.
Limitation of liability:
This Safe Harbor policy does not grant immunity from legal action by third parties or from actions initiated by law enforcement authorities, over which Defend.gl has no control.
Where relevant, however, Defend.gl will assist security researchers by providing context and documentation confirming that security research was carried out in good faith.
Greenlandic context:
Defend.gl operates within the framework of applicable Greenlandic and Danish law and works actively to promote clear and responsible frameworks for ethical security research in Greenland.
Legal disclaimer
This Safe Harbor policy does not constitute a legally binding contract but represents Defend.gl's commitment and intent. We reserve the right to update this policy. Material changes will be communicated via our platform.
Questions?
If you are unsure whether an activity is covered by Safe Harbor, contact us before you begin your research.
Ready to report?
Now that you know the rules, you are ready to report vulnerabilities safely and responsibly through our platform.