Dear Grist Users,
Grist had an outage this morning, which lasted about an hour. My sincere apologies for it, and many thanks for your patience.
We took the service into maintenance mode intentionally while looking into a potential security weakness caused by an update that we released last night.
The issue in question is a corner case — how access rules apply to summary tables. This combination is rarely used, but because it affects security and privacy of user data, we had to treat it as serious and urgent.
During the hour of the outage, we determined the precise list of documents affected, and rolled out a fix. With the fix in place, we restored the service for everyone not impacted, and followed up with affected users later. Thanks to the quick decision to pause the service, very few documents were affected, and it turns out that no sensitive data was leaked after all.
We know many of you use Grist for important and sensitive business and personal data. Today’s outage is a testament to how seriously we take data privacy and security.
Thank you for trusting our team and our software.
–
Dmitry Sagalovskiy
CEO, Grist Labs