ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review

aisecurity.llc

Vulnerability Disclosure Policy

Responsible disclosure · security@aisecurity.llc · Effective May 19, 2026

Report a vulnerability

Email your report to security@aisecurity.llc. Include a clear description, reproduction steps, and your assessment of impact. We will acknowledge within 48 hours and provide status updates throughout the investigation.

1. Our Commitment

aisecurity.llc is an AI security engineering firm. We take the security of our own services seriously and welcome responsible disclosure from the security research community. We commit to engaging with researchers in good faith, investigating reports promptly, and providing credit for valid discoveries.

We will not pursue legal action against researchers who discover and report vulnerabilities in good faith in accordance with this policy.

2. Scope

In Scope

The following are in scope for responsible disclosure:

  • aisecurity.llc web application and public services (aisecurity.llc)
  • Authentication and session management
  • Assessment workflows, credential verification pages, and client-facing portals operated by aisecurity.llc
  • API endpoints exposed by our site and services
  • Data exposure affecting users of our services

Out of Scope

The following are out of scope:

  • Denial-of-service attacks requiring large-scale traffic
  • Social engineering of aisecurity.llc staff or contractors
  • Physical attacks against infrastructure
  • Vulnerabilities in third-party services or dependencies (report to them directly)
  • Issues in our own published research or methodology documents (not security vulnerabilities)
  • Automated scanner results without demonstrated impact
  • Rate limiting or resource exhaustion without demonstrated data or account exposure

3. Vulnerability Severity

High Priority

  • Authentication bypass or privilege escalation
  • Unauthorized access to user data or accounts
  • SQL injection, remote code execution, SSRF
  • Cryptographic weaknesses exposing stored data
  • AIPSA credential forgery or manipulation

Medium Priority

  • Cross-site scripting (XSS) with meaningful data impact
  • CSRF with non-trivial security impact
  • Information disclosure revealing internal system details
  • Business logic flaws with security implications

Lower Priority

  • Self-XSS requiring extensive user interaction
  • Missing security headers without demonstrated exploitation path
  • Clickjacking on non-sensitive pages
  • Username enumeration without a practical attack path

4. How to Report

4.1 Primary Channel

Email security@aisecurity.llc with the subject line: Security Vulnerability — [Brief Title]

4.2 What to Include

  • Summary of the vulnerability
  • Affected URL, endpoint, or component
  • Vulnerability type (e.g., XSS, IDOR, SQLi)
  • Step-by-step reproduction instructions
  • Proof of concept (screenshots, HTTP traces, or code — as appropriate)
  • Your assessment of potential impact
  • Any remediation suggestions you have

4.3 Encrypted Reports

For particularly sensitive reports, request our PGP public key by emailing security@aisecurity.llc before sending sensitive details.

5. Response Process

1
AcknowledgmentWithin 48 hours

We confirm receipt of your report.

2
Triage3–5 business days

We assess severity, reproduce, and classify the issue.

3
InvestigationVaries by complexity

We investigate impact, determine root cause, and develop a fix.

4
ResolutionVaries by severity

We deploy a fix and verify it resolves the issue.

5
DisclosureCoordinated with reporter

We work with you on timing of any public disclosure.

6. Researcher Conduct

While conducting research, please:

  • Minimize any impact to site or service availability or other users
  • Do not access, modify, or exfiltrate user data beyond what is necessary to demonstrate the vulnerability
  • Use your own test accounts rather than real user accounts
  • Stop testing immediately if you encounter data that appears to belong to real users
  • Do not publicly disclose the issue before we have had a reasonable opportunity to respond

7. Recognition

We maintain a public Security Acknowledgments page for researchers who responsibly disclose valid vulnerabilities. We will credit you by name (or alias) with your permission.

We do not currently operate a paid bug bounty program. We are grateful for the time and expertise researchers invest and recognize it through public acknowledgment and, where appropriate, direct thanks from our security team.

Vulnerability Disclosure Policy · aisecurity.llc · Effective May 19, 2026 · Version 1.0

← Back to Legal