Legal · Security

Vulnerability disclosure

How to report a security issue affecting aaes.ai or client-operated AAES software that you deploy.

Last updated: Applies to aaes.ai and client-operated software
Two scopes

The public website, and client-operated software you deploy yourself.

Report by email

hello@aaes.ai, subject Security. Do not post details in a public issue.

Five business days

We acknowledge reports within five business days. There is no bug bounty.

Scope

This policy describes how to report a security issue affecting the aaes.ai website or client-operated AAES software that you deploy yourself. There is no AAES-hosted product cell.

The aaes.ai website. Good-faith research against the public website is in scope when it is limited to what is needed to demonstrate a vulnerability, does not degrade the site for others, does not access, alter, or exfiltrate another person's data, and does not introduce malware. Flooding, credential stuffing, and spam against the contact form are not good-faith research. Testing aaes.ai is otherwise out of scope except as this policy allows.

Client-operated AAES software. This covers software you obtained lawfully and deploy yourself, or that a client has authorized you to test. Reports that show a way to defeat a claimed control are in scope. Examples include obtaining, widening, or replaying a credential grant beyond policy; altering, omitting, or reordering a sealed record without detection; completing an irreversible action without the required approval by an authorized person; or leaking secrets into logs, pages, or error messages.

There is no AAES-hosted product cell to test. Do not scan for one. Do not attempt to obtain or test a private GitHub repository you have not been given. Do not test another organization's deployment without that client's authorization.

Known product limits are not treated as new findings. Those include that observation is not enforcement, that a default install may serve HTTP unless TLS is configured, and that no AAES-hosted cell exists.

How to report

Do not post vulnerability details in a public issue or public forum. Email us with the subject line Security.

To
hello@aaes.ai
Subject
Security

Include the affected system (the website, or the software version or commit if you know it), the property you believe is defeated, and the smallest reproduction you can manage. Remove credentials, private keys, and other people's data from the first message.

No encryption key is published yet. Do not wait for one before sending the first message. If the report is sensitive, say so in that message and we will agree a channel.

What to expect

Acknowledgment
Within five business days. If you hear nothing after seven business days, send again in the same thread. Silence is a failure on our side, not a filter.
Assessment
A substantive assessment within fifteen business days: whether the report reproduces, which claimed property it defeats, and whether it is in scope. We may ask for more information to reproduce the issue. If we dispute severity, we will say why in writing.
Fix or accepted risk
A confirmed defect is either fixed or recorded as an accepted risk, with the reason. You will be told which. A fix lands before any public description of the issue.
Coordinated disclosure
We ask for 90 days from acknowledgment before public discussion. We will credit you unless you ask us not to. If we need longer, we will say so and say why. If you have heard nothing substantive for 60 days after acknowledgment, you may disclose.

These response commitments are not a product availability SLA.

Safe harbor

If you act in good faith, stay within the scopes named above, do only what is needed to demonstrate the issue, do not access, alter, or exfiltrate another party's data, and do not degrade a service others use, then your research is authorized under this policy. We will not pursue or support legal action against you for that research.

Current assurance

Questions about this policy: hello@aaes.ai, subject Security. The same contact is published as an RFC 9116 security.txt at /.well-known/security.txt.

Related pages

Read the current security posture, including known limitations and how to evaluate them. For a design-partner discussion, use the contact form.