Legal and Policy

Security Disclosure Policy

Current public version of the Security Disclosure Policy.

Legal counsel review required

This page contains professional placeholder legal content. It should be reviewed, revised, and approved by qualified legal counsel before production use. Product capabilities do not by themselves create legal compliance or contractual commitments.

Version

1.0

Effective date

August 13, 2026

Last updated

August 14, 2026

Legal review notice: This placeholder disclosure policy should be reviewed by legal and security leadership before production use.

1. Responsible Disclosure

If a security researcher or customer identifies a potential vulnerability in the platform, the preferred approach is coordinated, private disclosure through the designated security contact. Public disclosure timelines should be agreed in good faith.

2. Submission Guidelines

Reports should include affected URLs or features, reproduction steps, observed impact, and any supporting evidence. Submitters should avoid accessing data beyond what is necessary to confirm the issue and should not disrupt service availability.

3. Out-of-Scope Conduct

Unauthorized data access, denial-of-service activity, social engineering against staff, malware submission, or attempts to obtain real credentials are out of scope and prohibited.

4. Contact Placeholder

Replace this section with the actual security reporting address, PGP or encrypted-submission instructions if used, and expected response windows.

Next steps before production use

  • Confirm legal entity names, governing law, and contact details with counsel.
  • Review privacy, retention, AI provider, and employee-notice language against real deployment choices.
  • Validate cookies, analytics, voice-recording, and subprocessors language against actual configuration.