Security
Vulnerability Disclosure Program
We build security software, so we hold our own surface to the same standard we hold yours. If you have found a vulnerability in a SecNode product or in our infrastructure, we want to hear about it — and we will not pursue you for telling us.
- Acknowledgement
- Within 2 business days
- Initial triage & severity
- Within 5 business days
- Remediation target, critical
- 90 days
- Coordinated disclosure
- Agreed with you, case by case
Safe harbour
We will not pursue or support legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We consider research conducted under it to be authorised, and we will say so publicly on your behalf if a third party questions it.
If you follow this policy and we believe you have acted in good faith, we will work with you to understand and resolve the issue quickly. Good faith is judged on what you did, not on what you found.
In scope
- secnode.ai, www.secnode.ai
- Marketing site and everything served from it.
- app.secnode.ai
- The SecNode console and its public API surface.
- *.secnode.ai
- Any other host under the domain, unless listed out of scope.
Scope is enforced automatically at intake. A report against a target outside this list is closed without triage, so please check the host before you spend time on it.
Out of scope
- Denial of service, volumetric or resource-exhaustion testing of any kind.
- Social engineering, phishing, or physical attacks against SecNode staff or offices.
- Automated scanner output submitted without a demonstrated, reproducible impact.
- Missing hardening headers, cookie flags or TLS configuration with no exploitable consequence.
- Vulnerabilities in third-party services we consume but do not operate.
- Findings that require a compromised device, a rooted browser, or physical access to a victim's session.
Ground rules
- Test only against assets in scope, and only with accounts you own.
- Stop at proof. Demonstrate the issue, then stop — do not pivot, escalate or persist.
- Never access, modify, exfiltrate or destroy data belonging to anyone else. If you encounter third-party data, stop and tell us immediately.
- Do not degrade availability for other users.
- Give us reasonable time to remediate before any public disclosure, and coordinate the timing with us.
Rewards
This is a disclosure programme, not a paid bug bounty — we do not currently offer monetary rewards. We do credit researchers who want to be named once an issue is resolved, and we will say plainly what we fixed and when.
Submit a report
Prefer email? Write to security@secnode.ai. Machine-readable contact details are published at /.well-known/security.txt.