Coordinated disclosure is how the security community keeps everyone safer. We ask researchers to give us a fair chance to fix an issue before it is made public, and in return we commit to handling every report quickly, transparently, and without legal threat to anyone acting in good faith. We hold ourselves to the same standard when we are the ones who find a flaw.
Email [email protected] with enough detail for us to reproduce the issue: the affected system or URL, the steps to trigger it, and the impact you observed. Where you can, include a proof of concept. If you would like to send sensitive details encrypted, ask us and we will provide a key.
Please give us a reasonable period to investigate and remediate before any public disclosure. As a guide, we aim to resolve an issue or share a concrete remediation plan within 90 days of a valid report, and we will keep you informed throughout rather than leave you waiting in silence.
We will not pursue or support legal action against anyone who discovers and reports a vulnerability in line with this policy. We consider good-faith security research to be authorised conduct, and we would far rather work with you than against you.
To stay within good faith, please:
Our work involves examining how AI agents and the systems around them behave, and in the course of that we may discover a vulnerability in third-party software, in a service we use, or inside a customer's environment.
When we do, we practise the same coordinated disclosure we ask of others. We report the issue privately to the affected party, give them a fair window to remediate before any public discussion, take only the access needed to establish the finding, and follow the vendor's or customer's disclosure process where one exists. Vulnerabilities found inside a customer's estate are reported to that customer directly and in confidence, and we never disclose a customer's vulnerabilities publicly.