Vulnerability Disclosure Policy
Security research is our trade, and we welcome it aimed at us. If you believe you have found a vulnerability in any SafeDescent system, we want to hear about it, and this policy tells you how.
Scope
This policy covers safedescent.ai and its subdomains, including the ERA assessment application. It does not cover third-party services we merely link to, or infrastructure operated by our providers, which have their own disclosure programs.
How to report
Email [email protected] with “Vulnerability report” in the subject line. Include what you found, where, the steps to reproduce it, and your assessment of the impact. Proof-of-concept material is welcome; working exploits against production data are not required and not encouraged. A machine-readable pointer to this policy is published at /.well-known/security.txt.
What we ask of you
- Make a good-faith effort to avoid privacy violations, data destruction, and service degradation. Do not run denial-of-service tests.
- Access only your own data. If you encounter someone else’s data, stop, note what happened, and report it to us.
- No social engineering of our team and no physical attacks.
- Give us a reasonable window to fix the issue before any public disclosure. Ninety days from your report is our default; we are happy to coordinate timelines.
What you can expect from us
We will acknowledge your report within five business days, keep you informed as we triage and fix, and tell you when the issue is resolved. With your permission, we will credit you publicly. We do not currently run a paid bounty program, and we say so here rather than let you find out after the work.
Safe harbor
We will not pursue legal action against research conducted in good faith and within this policy, and we consider such research authorized under applicable anti-hacking and anti-circumvention laws to the extent we can grant that authorization. If a third party takes action against you for activity this policy permits, we will make it known that you acted within our published rules.