generated: '2026-09-12' method: searched source: https://www.graphicpkg.com/disclosures-and-company-policies/vulnerability-disclosure-policy/ program: published: true name: Graphic Packaging International Vulnerability Disclosure Policy url: https://www.graphicpkg.com/disclosures-and-company-policies/vulnerability-disclosure-policy/ http_status: 200 discovered_via: www.graphicpkg.com/page-sitemap.xml scope: >- "Any digital asset owned, operated, or maintained by GPI, including public websites *.graphicpkg.com" — quoted from the policy page. reporting: channel: email contact: bugreporting@graphicpkg.com form: null pgp_key: null safe_harbor: stated: false note: >- The policy states no explicit legal safe harbor. It frames the relationship as mutual expectation: GPI commits to "trust and confidentiality" and asks researchers to avoid privacy violations and disruptive testing. response_commitment: sla: null note: >- "The GPI Security team will conduct a comprehensive investigation and take appropriate action for resolution." No acknowledgement, triage or remediation timeline is published. bug_bounty: offered: false platform: null note: >- The policy is explicit: "GPI does not offer compensation in exchange for identification of potential issues." security_txt: served: false note: >- No RFC 9116 /.well-known/security.txt is served on any graphicpkg.com host — see well-known/graphic-packaging-well-known.yml. Publishing one that carries Contact: mailto:bugreporting@graphicpkg.com and Policy: the URL above would make this program machine-discoverable at no cost.