Security

Vulnerability Disclosure Program

Security researchers help us keep Vals AI and our users safe. This policy explains which systems may be tested, how to test them responsibly, and how to report a potential vulnerability directly to us.

Effective August 31, 2026

Authorization

If you make a good-faith effort to comply with this policy during your security research, we will consider your research to be authorized, work with you to understand and resolve the issue, and Vals AI will not recommend or pursue legal action related to your research. If legal action is initiated by a third party against you for activities conducted in accordance with this policy, we will make this authorization known.

This authorization applies only to systems Vals AI owns or operates and only to activity that follows this policy. We cannot authorize testing of third-party systems or promise how a third party will respond.

Scope

This policy applies to:

  • Internet-accessible systems and services on vals.ai and its subdomains that are owned and operated by Vals AI.

Third-party services, customer-controlled systems or data, linked websites, and systems that Vals AI does not own or operate are out of scope, even when they integrate with or are reachable from a Vals AI service.

If you are unsure whether a system is in scope, email us before testing it.

Responsible research guidelines

Under this policy, you must:

  • Use accounts you own and test data you are authorized to access.
  • Make every effort to avoid privacy violations, degraded user experience, disruption to production systems, and the destruction or manipulation of data.
  • Use an exploit only as far as needed to confirm that a vulnerability exists. Do not establish persistence, pivot to other systems, or expand access beyond the minimum proof.
  • Stop testing and notify us immediately if you encounter user data, credentials, confidential information, or other sensitive data. Do not copy, download, retain, use, or disclose that data.
  • Notify us as soon as possible after discovering a real or potential security issue and provide us a reasonable amount of time to investigate and remediate it.
  • Comply with applicable law and keep vulnerability details confidential while we coordinate remediation with you.

Testing that is not authorized

Do not conduct:

  • Denial-of-service, distributed denial-of-service, resource-exhaustion, or other availability testing.
  • High-volume automated testing that could degrade a service or create excessive traffic.
  • Social engineering, phishing, vishing, spam, physical security testing, or attacks against Vals AI personnel, contractors, customers, or users.
  • Credential stuffing, brute-force attacks, malware deployment, or attempts to access another person's account.
  • Destructive testing or any modification, deletion, downloading, or exfiltration of data that is not your own.
  • Testing of vendors, open-source projects, or other third parties without their separate authorization.

If you unintentionally cross one of these boundaries while conducting otherwise good-faith research, stop testing and tell us promptly. We would rather receive a complete, candid report than have an accidental overstep go unreported. This does not authorize intentional, reckless, or repeated violations of these rules.

Generally out-of-scope findings

The following are generally not treated as vulnerabilities unless your report demonstrates a concrete security impact:

  • Clickjacking on pages without sensitive actions; self-XSS; content spoofing; or open redirects without additional impact.
  • Rate-limit observations, username or email enumeration, and software version disclosure without a viable exploitation path.
  • AI model output, prompt-injection, or jailbreak behavior that does not cross a security boundary or affect the confidentiality, integrity, or availability of a Vals AI system or user data.

Report a vulnerability

Email your report to us. Reports may be submitted anonymously, though providing a way to contact you helps us ask follow-up questions and share updates. Please write in English if possible.

Title
Vulnerability report: [brief description]
Email body
Affected asset or URL:
Vulnerability type:
Description and potential impact:
Steps to reproduce:
Proof of concept or supporting evidence:
Date and time observed (including time zone):
Disclosure plans, if any:
Preferred name or handle for credit (optional):

Include only the minimum sensitive information needed to explain the issue. Do not send secrets, personal data, executable files, or data belonging to another person. If a report requires a safer transfer method, say so in your first email and we will coordinate one with you.

What you can expect from us

If you provide contact information, we will aim to:

  • Acknowledge your report within five business days.
  • Confirm whether the issue can be reproduced and keep you informed of material progress, to the best of our ability.
  • Prioritize remediation based on severity, exploitability, and impact.
  • Coordinate the timing of any public disclosure and credit you if you want recognition.

We may share a report with an affected vendor when needed to investigate or remediate the issue. We will not share your identity without your permission unless required by law.

Coordinated disclosure

Please do not publicly disclose a vulnerability until it has been remediated or 90 calendar days have passed since we acknowledged your report, whichever comes first, unless we agree on a different timeline. We may ask for additional time when a fix depends on a third party or requires a complex change, and we will explain why. Sensitive or personal data must never be publicly disclosed.

Program terms

This is a vulnerability disclosure program, not a bug bounty. Vals AI does not currently offer payment or other compensation for reports, and submitting a report does not create a right to compensation.

We may update this policy as our systems and program evolve. Questions about this policy can be sent to security@vals.ai.