Legal · Security

Responsible Disclosure Policy

Last updated: 1 May 2026

Report a Vulnerability

To report a security vulnerability, email our security team at support@aiconsortium.cloud. For sensitive reports, request our PGP public key by emailing this address first.

We acknowledge all valid reports within 48 hours and provide a resolution timeline within 7 business days.

1. Our Commitment

AICONSORTIUM is committed to the security of our AI systems, APIs, and infrastructure. We welcome responsible disclosure of vulnerabilities from the security research community. We will work transparently with researchers who report issues in good faith, and we commit to: acknowledging valid reports promptly; keeping you informed of our progress; crediting researchers (with permission); and not pursuing legal action against researchers who act in accordance with this policy.

2. Scope

This policy applies to vulnerabilities in:

  • aiconsortium.cloud and all subdomains
  • The Clark and Sattam.ai APIs
  • AICONSORTIUM mobile applications (when available)
  • AI safety and alignment vulnerabilities in our model outputs
  • Authentication and authorisation systems

Out of scope: third-party services we use (report to them directly); social engineering attacks; physical security; denial-of-service attacks.

3. What to Report

We are particularly interested in:

  • Authentication bypass or privilege escalation
  • API key exposure or credential leakage
  • Prompt injection attacks that lead to data exfiltration or system compromise
  • Model jailbreaks that produce content violating our Usage Policy at scale
  • IDOR (Insecure Direct Object Reference) vulnerabilities
  • XSS, CSRF, and injection vulnerabilities in our web properties
  • Data exposure (other users' data accessible to you)

4. Rules of Engagement

When researching vulnerabilities, you must:

  • Only test against accounts you own or have explicit permission to test
  • Not access, modify, or delete data belonging to other users
  • Not exploit vulnerabilities beyond what is necessary to demonstrate the issue
  • Not perform denial-of-service or load testing
  • Report issues promptly rather than accumulating access or data
  • Maintain confidentiality until we have issued a fix or confirmed no fix is required

5. Resolution Process

Upon receiving a valid report, we will: acknowledge within 48 hours; triage and confirm severity within 7 business days; provide a remediation timeline; notify you when the vulnerability is patched; and credit you in our security acknowledgements (with your permission) if you are the first to report a valid issue.

6. Contact

Security team: support@aiconsortium.cloud
For AI safety concerns specifically: support@aiconsortium.cloud