Security · coordinated disclosure
Report a vulnerability.
Found a security issue in a CSOAI system? Tell us privately and we'll fix it — good-faith research is welcome, and we practise coordinated disclosure. An AI-governance company should be the safest system you run.
Email [email protected] with details and reproduction steps. Do not disclose publicly until we've coordinated a fix.
We aim to acknowledge within 72 hours and give you a tracking reference.
We validate, assess severity, and work a remediation — keeping you updated. Actively-exploited issues are prioritised.
We agree a disclosure timeline with you and credit you (if you wish) once a fix is available.
Frequently asked
How do I report a security vulnerability to CSOAI?
Email [email protected] with a description, affected component and reproduction steps. Our machine-readable policy is published at /.well-known/security.txt. Please report privately and give us reasonable time to remediate before any public disclosure.
Does CSOAI offer safe harbor for good-faith research?
Yes. We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and follow this coordinated disclosure policy.
What is coordinated vulnerability disclosure?
Coordinated vulnerability disclosure (CVD) is the practice of reporting a vulnerability privately to the vendor, allowing time for a fix, and then disclosing publicly in a coordinated way. It mirrors the EU Cyber Resilience Act's vulnerability-handling and reporting duties.