Introducing the SecNode Memory Layer

Security

Vulnerability Disclosure Program

We build security software, so we hold our own surface to the same standard we hold yours. If you have found a vulnerability in a SecNode product or in our infrastructure, we want to hear about it — and we will not pursue you for telling us.

Acknowledgement
Within 2 business days
Initial triage & severity
Within 5 business days
Remediation target, critical
90 days
Coordinated disclosure
Agreed with you, case by case

Safe harbour

We will not pursue or support legal action against security researchers who discover and report vulnerabilities in good faith and in accordance with this policy. We consider research conducted under it to be authorised, and we will say so publicly on your behalf if a third party questions it.

If you follow this policy and we believe you have acted in good faith, we will work with you to understand and resolve the issue quickly. Good faith is judged on what you did, not on what you found.

In scope

secnode.ai, www.secnode.ai
Marketing site and everything served from it.
app.secnode.ai
The SecNode console and its public API surface.
*.secnode.ai
Any other host under the domain, unless listed out of scope.

Scope is enforced automatically at intake. A report against a target outside this list is closed without triage, so please check the host before you spend time on it.

Out of scope

  • Denial of service, volumetric or resource-exhaustion testing of any kind.
  • Social engineering, phishing, or physical attacks against SecNode staff or offices.
  • Automated scanner output submitted without a demonstrated, reproducible impact.
  • Missing hardening headers, cookie flags or TLS configuration with no exploitable consequence.
  • Vulnerabilities in third-party services we consume but do not operate.
  • Findings that require a compromised device, a rooted browser, or physical access to a victim's session.

Ground rules

  • Test only against assets in scope, and only with accounts you own.
  • Stop at proof. Demonstrate the issue, then stop — do not pivot, escalate or persist.
  • Never access, modify, exfiltrate or destroy data belonging to anyone else. If you encounter third-party data, stop and tell us immediately.
  • Do not degrade availability for other users.
  • Give us reasonable time to remediate before any public disclosure, and coordinate the timing with us.

Rewards

This is a disclosure programme, not a paid bug bounty — we do not currently offer monetary rewards. We do credit researchers who want to be named once an issue is resolved, and we will say plainly what we fixed and when.

Submit a report

All fields are required unless marked optional.

One line — what the vulnerability is, and where.

The exact URL or endpoint. Targets outside the scope listed above are not eligible and are closed without triage.

Closest category.

Severity

Your assessment — triage assigns the final rating.

What the vulnerability is, and its impact. What could an attacker actually do with it?

Steps to reproduce from a clean session. Include the requests, payloads and what you observed.

Screenshots (optional)

PNG, JPEG, GIF or WebP · up to 4 files, 150 KB in total. For larger evidence, reply to your confirmation email.

Where your confirmation and any follow-up goes. Used only for this report.

Encrypted in transit and delivered directly to the SecNode security team.

Prefer email? Write to security@secnode.ai. Machine-readable contact details are published at /.well-known/security.txt.