Security · coordinated disclosure

Report a vulnerability.

Found a security issue in a CSOAI system? Tell us privately and we'll fix it — good-faith research is welcome, and we practise coordinated disclosure. An AI-governance company should be the safest system you run.

1 · Report privately

Email [email protected] with details and reproduction steps. Do not disclose publicly until we've coordinated a fix.

2 · Acknowledgement

We aim to acknowledge within 72 hours and give you a tracking reference.

3 · Triage & fix

We validate, assess severity, and work a remediation — keeping you updated. Actively-exploited issues are prioritised.

4 · Coordinated disclosure

We agree a disclosure timeline with you and credit you (if you wish) once a fix is available.

Safe harbor: we won't pursue legal action against good-faith research that respects privacy, avoids service disruption, and follows this policy. Please don't access data that isn't yours, and give us reasonable time to remediate before public disclosure.

Frequently asked

How do I report a security vulnerability to CSOAI?

Email [email protected] with a description, affected component and reproduction steps. Our machine-readable policy is published at /.well-known/security.txt. Please report privately and give us reasonable time to remediate before any public disclosure.

Does CSOAI offer safe harbor for good-faith research?

Yes. We will not pursue or support legal action against researchers who act in good faith, avoid privacy violations and service disruption, and follow this coordinated disclosure policy.

What is coordinated vulnerability disclosure?

Coordinated vulnerability disclosure (CVD) is the practice of reporting a vulnerability privately to the vendor, allowing time for a fix, and then disclosing publicly in a coordinated way. It mirrors the EU Cyber Resilience Act's vulnerability-handling and reporting duties.