NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Vulnerability Disclosure Policy

We welcome good-faith reports of vulnerabilities in aisecurity.llc systems. This policy explains what is in scope, what is out of scope, how to report issues safely, and what testing is not authorized without written permission.

Responsible disclosureNo bounty promised unless separately stated

Report vulnerabilities in aisecurity.llc systems. Do not access, modify, destroy, or exfiltrate customer data. Do not test third-party systems or customer environments. Do not perform denial-of-service, phishing, social engineering, malware, or destructive testing. Stop when impact is proven. No bounty is promised unless a separate program says so.

1. Plain-English Summary

  • Report vulnerabilities in aisecurity.llc systems.
  • Do not access, modify, destroy, or exfiltrate customer data.
  • Do not test third-party systems or customer environments.
  • Do not perform denial-of-service, phishing, social engineering, malware, or destructive testing.
  • Stop when impact is proven.
  • No bounty is promised unless a separate program says so.

2. In-Scope Assets

Where available, the following are in scope for responsible disclosure:

  • Public website.
  • Trust center and legal routes.
  • Platform and customer portal.
  • /scope and /start flows.
  • Private offers and contract packet access.
  • Authentication and session flows.
  • Account, organization, workspace, and tenant boundaries.
  • Roles, entitlements, seats, and permissions.
  • Stripe, checkout, and entitlement provisioning logic.
  • SecEng Copilot.
  • Packet, report, and evidence rendering.
  • Uploaded artifacts and evidence files.
  • API routes and webhooks.
  • SSO, SAML, OIDC, and SCIM implementation.
  • OAuth and SaaS integrations and callbacks.
  • Browser extension.
  • Native app.
  • Runtime proxy, model gateway, or trace tooling.
  • Code scanner.
  • Adversarial range.
  • RAG harness.
  • Artifact analyzer.
  • LMS and training access.

3. High-Value Findings

  • Authentication bypass.
  • Session weakness.
  • IDOR.
  • Tenant or workspace isolation failure.
  • Role or entitlement escalation.
  • Unauthorized contract or private-offer access.
  • Evidence or artifact exposure.
  • Uploaded file exposure.
  • Copilot prompt or evidence leakage.
  • OAuth token exposure.
  • SSO or SCIM provisioning flaw.
  • Stripe or seat provisioning abuse.
  • XSS or CSRF.
  • SSRF or RCE.
  • Secrets leakage.
  • Badge, attestation, or claim tampering.
  • Unauthorized report or packet access.
  • API authorization flaws.

4. Out of Scope

  • Denial-of-service or stress testing.
  • Phishing or social engineering.
  • Malware.
  • Physical attacks.
  • Credential stuffing or password spraying.
  • Spam.
  • Attacks against third-party providers.
  • Attacks against customer environments.
  • Accessing other customers' data.
  • Modifying or deleting customer data.
  • Exfiltration beyond minimal proof.
  • Automated high-volume scanning.
  • Persistence.
  • Destructive testing.
  • Bypassing payment to obtain paid services.
  • Testing cloud or SaaS provider infrastructure directly.

5. Third-Party Integrations

Do not test third-party providers directly through this program. Report provider vulnerabilities to the provider. Report vulnerabilities in aisecurity.llc integration logic, token handling, callback validation, tenant isolation, or authorization to us.

6. Safe Testing Rules

  • Use your own account or workspace.
  • Do not access other users' or customers' data.
  • Minimize proof.
  • Stop when impact is demonstrated.
  • Avoid privacy harm.
  • Avoid service disruption.
  • Do not publicly disclose before coordination.
  • Do not use findings to extort, threaten, or pressure.
  • Report promptly.

7. How to Report

Please include:

  • Affected URL or feature.
  • Steps to reproduce.
  • Impact.
  • Account or workspace used.
  • Timestamp.
  • Screenshots or video only if safe and redacted.
  • Suggested severity.
  • Contact information.
  • Whether any customer data may have been exposed.

Send reports to security@aisecurity.llc. If you need encryption, request a PGP public key before sending sensitive details.

8. Response Expectations

  • We aim to acknowledge and triage reports when possible.
  • Remediation priority depends on severity and exploitability.
  • We may ask for clarification.
  • We may not respond to spam, low-quality automated scans, or out-of-scope reports.
  • No bounty is promised unless separately stated.

9. Safe Harbor

Good-faith research that follows this policy is welcomed. This policy does not authorize unlawful activity, access to customer data, testing outside scope, disruption, or violation of third-party terms. If in doubt, ask first.

Vulnerability Disclosure Policy · aisecurity.llc · Effective June 27, 2026 · Version 1.0

← Back to Legal