AIDEFEND Labs
  • Open Frameworks
  • Solutions
  • AIDEFEND in Action AIDEFEND SecureFlow
  • About
  • Explore AIDEFEND
Security

Vulnerability Disclosure Policy

Last updated: July 14, 2026

AIDEFEND Labs welcomes good-faith security research. This policy explains how to report a vulnerability in a system that we own or operate and how to conduct research safely.

Report a vulnerability

1. Scope

This policy applies to security vulnerabilities in systems and services that AIDEFEND Labs owns and operates, including:

  • Web content and services served directly from aidefendlabs.com.
  • The public AIDEFEND framework website served from aidefend.net.
  • AIDEFEND-operated service endpoints that expressly identify AIDEFEND Labs as the operator.
  • Security defects in AIDEFEND-maintained open-source code that could create a real confidentiality, integrity, or availability impact for users.

If you are unsure whether an asset is in scope, contact us before testing it.

2. AI security issues

We treat AI security findings as vulnerabilities when they demonstrate a meaningful security impact. Examples that may be in scope include:

  • Prompt injection that produces unauthorized access, tool execution, data disclosure, or a durable security-policy bypass.
  • Cross-user or cross-tenant data exposure.
  • Authentication, authorization, identity, or permission bypass.
  • Unauthorized agent actions or compromise of an agent, model, tool, memory, retrieval, or control-plane boundary.
  • Supply-chain vulnerabilities in AIDEFEND-operated software or services.

Content-quality issues, hallucinations, harmless jailbreaks, policy disagreements, and model outputs without a demonstrated security impact are not treated as vulnerabilities under this policy.

3. Out of scope

  • Denial-of-service testing, traffic flooding, destructive testing, or tests that impair availability.
  • Social engineering, phishing, physical attacks, or attempts to access employees' or users' personal accounts.
  • Accessing, modifying, retaining, or disclosing data beyond the minimum necessary to demonstrate a vulnerability.
  • Testing third-party services, platforms, repositories, or infrastructure that AIDEFEND Labs does not operate.
  • Automated scanning that creates unreasonable traffic or does not include manual validation of the reported impact.
  • Reports that only identify missing security headers, version banners, or best-practice observations without a credible exploit path or security impact.

4. Research guidelines

When conducting research:

  • Make a good-faith effort to avoid privacy violations, service disruption, data destruction, and harm to others.
  • Use your own accounts and data whenever possible.
  • Stop testing and report the issue if you encounter sensitive data or gain access beyond what is necessary to prove the finding.
  • Do not use a vulnerability to pivot into other systems, establish persistence, or extract data.
  • Give us a reasonable opportunity to investigate and remediate the issue before public disclosure.
  • Comply with applicable law.

5. How to report

Email edward@aidefendlabs.com and include:

  • The affected domain, endpoint, repository, version, or component.
  • A concise description of the vulnerability and demonstrated security impact.
  • Reproduction steps, proof-of-concept material, and any prerequisites.
  • Whether you accessed any data and what you did with it.
  • Your preferred contact information and, if desired, how you would like to be credited.

Please do not include secrets, unnecessary personal information, or data belonging to other people in the initial report.

6. What you can expect

We aim to acknowledge reports within five business days and provide an initial assessment or status update within ten business days. Resolution time depends on severity, complexity, affected dependencies, and the coordination required. We will make a reasonable effort to keep you informed and to coordinate any public disclosure.

7. Safe harbor

If you conduct research in good faith and make a reasonable effort to follow this policy, we will consider your research authorized under this policy and will not initiate or support legal action based solely on that compliant research. If your activity or report raises a concern that is not clearly addressed here, contact us before proceeding.

This safe-harbor statement does not authorize activity against third-party systems and cannot bind independent third parties or law-enforcement authorities.

8. Rewards and acknowledgment

AIDEFEND Labs does not currently operate a bug bounty program. Submission of a report does not create an entitlement to payment. We may acknowledge helpful researchers with their permission, but acknowledgment is not guaranteed.

9. Security contact

Report vulnerabilities to edward@aidefendlabs.com. Machine-readable contact information is also available at /.well-known/security.txt.

AIDEFEND Labs
Public Benefit Corporation
AIDEFEND Framework AIDEFEND in Action MCP Service GitHub LinkedIn Privacy Notice Terms of Use Vulnerability Disclosure
© 2026 AIDEFEND Labs, PBC. All rights reserved.
Open frameworks, practical defenses, and real-world AI security analysis that help teams reduce technical risk.