Security at GUBUS

GUBUS minimizes Google authorization, encrypts stored credentials, separates project principals and records security-relevant operations. The central application uses drive.file instead of whole-Drive access.

Responsible disclosure

Report a suspected vulnerability to security@gubus.io. Include the affected URL or component, reproduction steps and impact. Do not access other users’ data, disrupt production or publicly disclose an unresolved issue.

What to expect

We will acknowledge the report, investigate it, coordinate remediation and keep you informed through the reporting address. A formal response-time commitment will be published after the security mailbox and incident workflow are operationally verified.

Account safety

You can revoke GUBUS from Google Account permissions. For suspected account compromise, revoke first and contact support@gubus.io.