Reporting
Email [email protected]. The machine-readable version of this contact is at /.well-known/security.txt, per RFC 9116.
A useful report contains: the URL or component affected, what you did, what happened, why it matters, and anything needed to reproduce it. A short proof of concept is welcome. Screenshots and raw requests are more useful than scanner output.
Report in English. One issue per email, where you can.
What we commit to
- We acknowledge a report within three business days.
- We tell you our assessment, and whether we are treating it as a vulnerability, within ten business days.
- We tell you when it is fixed.
- We credit you by name or handle when we describe the issue, if you want that and the report was in good faith. Say so in your email either way.
- We do not pursue legal action against researchers who follow this policy.
We do not currently run a paid bug bounty. We say so plainly rather than implying one.
Scope
In scope: defensiveai.org, www.defensiveai.org, and any other host we operate and identify as ours, including the infrastructure that serves this site and the evaluation form endpoint.
Out of scope:
- Client systems and client code. Nothing belonging to a client of ours is in scope under this policy, even if you learned of it through us. Report those to the client.
- Third-party services we merely use, where the weakness is theirs. Report to them; tell us too if it affects us.
- Denial of service, volumetric testing, and anything that degrades service for others.
- Social engineering of our people, our clients, or our providers. Physical attacks.
- Spam, mail-configuration findings with no demonstrated impact, missing hardening headers with no demonstrated impact, and reports produced entirely by a scanner with no verification.
Rules for testing
- Access only data that is yours or that you created for the test. Stop at the point where you have demonstrated the issue.
- If you encounter personal data or client material, stop immediately, do not save it, and tell us what you saw so we can measure exposure.
- Do not modify or delete data. Do not degrade service. Do not install persistence.
- Do not use a finding to pivot further into our systems.
- Give us reasonable time to fix before publishing. Ninety days from acknowledgement is our default, and we will agree a shorter or longer window with you where the facts call for it. If we cannot fix within the window, we will tell you why and we will not ask you to stay quiet indefinitely.
Safe harbor
Research conducted in accordance with this policy is authorized by us. We will treat it as authorized access under applicable computer-misuse and anti-hacking law, we will not bring a claim against you for it, and if a third party brings one arising from research that followed this policy, we will make that authorization clear.
This authorization is ours to give only for systems we operate. It does not extend to client systems, third-party services, or anything outside the scope above. If you are unsure whether something is ours, ask at [email protected] before testing.
If you found it in a client system
Report it to that client directly. We will not confirm or deny that any organization is a client of ours, and we will not pass a report along in a way that identifies you without your consent.
Last updated 14 September 2026. Questions about this document: [email protected]. Related: Terms · Privacy · Disclosure policy.