Responsible disclosure

Effective 5 August 2026

If you have found a vulnerability, we want to hear about it, and we will not take legal action against you for telling us. Write to our contact form. Our machine-readable contact is at /.well-known/security.txt.

What we promise

  • An acknowledgement from a person within two working days.
  • An assessment, with our severity view and a target fix date, within ten working days.
  • Credit in the fix note if you want it, and none if you would rather stay anonymous.
  • No legal action, and no complaint to your employer or host, for research conducted within this policy.

We do not operate a paid bounty. We would rather tell you that plainly than imply one exists.

In scope

  • The console, the public API, and the widget on any origin we control.
  • Authentication, session handling and the origin allowlist.
  • Tenant isolation, anything that lets one workspace read or affect another is our highest severity, and we would like to know today rather than next week.
  • Server-side request forgery through any URL we fetch on your behalf, including crawl targets and store connections.
  • Prompt injection that causes the assistant to exfiltrate another tenant's data or call a tool it should not.

Out of scope

  • Findings from automated scanners with no demonstrated impact.
  • Missing headers or cookie flags with no exploitable consequence.
  • Rate limiting on unauthenticated endpoints, unless you can show real amplification.
  • Social engineering of our staff or our customers.
  • Getting the assistant to say something rude. Interesting, occasionally; a vulnerability, no.

Two things we ask

Do not test against another customer's workspace. Their conversations belong to their visitors. Ask us and we will give you one of ours, with real configuration and no real people in it.

Do not exfiltrate data to prove a point. One record, or a redacted screenshot, establishes access. Pulling a table does not make the report stronger and does make it a breach we have to notify.

Disclosure timing

We aim to fix high-severity issues within 30 days and will keep you updated if something takes longer. Please give us 90 days before publishing, or less by agreement if the fix ships sooner. If we go quiet on you for two weeks, treat that as a failure on our part and say so: we would rather be chased than have a report expire in an inbox.