TESSERACT

Responsible Disclosure

Last updated: 28 July 2026
This policy covers disclosure in both directions: how to report a vulnerability you find in TESSERACT, and how we handle vulnerabilities we discover elsewhere in the course of our work. It applies to our product, our infrastructure, and this website.

Coordinated disclosure is how the security community keeps everyone safer. We ask researchers to give us a fair chance to fix an issue before it is made public, and in return we commit to handling every report quickly, transparently, and without legal threat to anyone acting in good faith. We hold ourselves to the same standard when we are the ones who find a flaw.

If you find something in TESSERACT

Reporting a vulnerability to us

Email [email protected] with enough detail for us to reproduce the issue: the affected system or URL, the steps to trigger it, and the impact you observed. Where you can, include a proof of concept. If you would like to send sensitive details encrypted, ask us and we will provide a key.

Please give us a reasonable period to investigate and remediate before any public disclosure. As a guide, we aim to resolve an issue or share a concrete remediation plan within 90 days of a valid report, and we will keep you informed throughout rather than leave you waiting in silence.

Scope

Our promise to researchers

Safe harbour for good-faith research

We will not pursue or support legal action against anyone who discovers and reports a vulnerability in line with this policy. We consider good-faith security research to be authorised conduct, and we would far rather work with you than against you.

To stay within good faith, please:

What happens after you report

What you can expect from us

Disclosure the other way

When we find a vulnerability elsewhere

Our work involves examining how AI agents and the systems around them behave, and in the course of that we may discover a vulnerability in third-party software, in a service we use, or inside a customer's environment.

When we do, we practise the same coordinated disclosure we ask of others. We report the issue privately to the affected party, give them a fair window to remediate before any public discussion, take only the access needed to establish the finding, and follow the vendor's or customer's disclosure process where one exists. Vulnerabilities found inside a customer's estate are reported to that customer directly and in confidence, and we never disclose a customer's vulnerabilities publicly.

Contact

For all disclosure matters, contact [email protected]. For our broader security posture and compliance path, see our Security & Compliance page.