Security & Responsible Disclosure
Last updated: August 1, 2026
Reporting a Vulnerability
If you believe you have discovered a security vulnerability in any AIOpenSec-owned property, we encourage you to report it to us responsibly.
Please send reports to: [email protected]
Include a clear description, affected URLs or components, step-by-step reproduction instructions, and the potential impact. We will acknowledge your report within 5 business days.
Scope
This policy covers publicly accessible AIOpenSec websites and services, including:
- Websites under the aiopensec.com domain
- Public APIs hosted at *.aiopensec.com
- Official AIOpenSec browser extensions and applications
Out of scope: third-party services not operated by AIOpenSec, social engineering, physical security testing, and denial-of-service attacks.
Responsible Disclosure Guidelines
- Provide us with reasonable time to investigate and remediate before public disclosure.
- Do not access, modify, delete, or exfiltrate data that does not belong to you.
- Avoid actions that could degrade the availability of our services.
- Do not share your findings with third parties until we have resolved the issue.
Our Commitment to You
- Acknowledge receipt of your report within 5 business days.
- Investigate the issue promptly and keep you informed.
- Not take legal action against you for good-faith research that complies with this policy.
- Publicly credit you for the discovery if you wish, once the issue is resolved.
AIOpenSec does not currently operate a paid bug bounty program, but we are grateful for responsible disclosures and will provide public recognition for valid reports.
Security Measures
We apply a defence-in-depth approach to protect our website and users:
- HTTPS enforced across all public endpoints
- Security headers including CSP, HSTS, and X-Frame-Options
- Rate limiting on public forms and APIs
- Input validation and output encoding
- Regular dependency audits and automated security updates
- ISO 27001:2022 certified information security management
Contact
Email: [email protected]
Address: AIOpenSec Labs Ltd, Vyman House, 104 College Road, 3rd Floor, Harrow, HA1 1BQ, United Kingdom