1. Scope
This policy applies to security vulnerabilities in systems and services that AIDEFEND Labs owns and operates, including:
- Web content and services served directly from
aidefendlabs.com. - The public AIDEFEND framework website served from
aidefend.net. - AIDEFEND-operated service endpoints that expressly identify AIDEFEND Labs as the operator.
- Security defects in AIDEFEND-maintained open-source code that could create a real confidentiality, integrity, or availability impact for users.
If you are unsure whether an asset is in scope, contact us before testing it.
2. AI security issues
We treat AI security findings as vulnerabilities when they demonstrate a meaningful security impact. Examples that may be in scope include:
- Prompt injection that produces unauthorized access, tool execution, data disclosure, or a durable security-policy bypass.
- Cross-user or cross-tenant data exposure.
- Authentication, authorization, identity, or permission bypass.
- Unauthorized agent actions or compromise of an agent, model, tool, memory, retrieval, or control-plane boundary.
- Supply-chain vulnerabilities in AIDEFEND-operated software or services.
Content-quality issues, hallucinations, harmless jailbreaks, policy disagreements, and model outputs without a demonstrated security impact are not treated as vulnerabilities under this policy.
3. Out of scope
- Denial-of-service testing, traffic flooding, destructive testing, or tests that impair availability.
- Social engineering, phishing, physical attacks, or attempts to access employees' or users' personal accounts.
- Accessing, modifying, retaining, or disclosing data beyond the minimum necessary to demonstrate a vulnerability.
- Testing third-party services, platforms, repositories, or infrastructure that AIDEFEND Labs does not operate.
- Automated scanning that creates unreasonable traffic or does not include manual validation of the reported impact.
- Reports that only identify missing security headers, version banners, or best-practice observations without a credible exploit path or security impact.
4. Research guidelines
When conducting research:
- Make a good-faith effort to avoid privacy violations, service disruption, data destruction, and harm to others.
- Use your own accounts and data whenever possible.
- Stop testing and report the issue if you encounter sensitive data or gain access beyond what is necessary to prove the finding.
- Do not use a vulnerability to pivot into other systems, establish persistence, or extract data.
- Give us a reasonable opportunity to investigate and remediate the issue before public disclosure.
- Comply with applicable law.
5. How to report
Email edward@aidefendlabs.com and include:
- The affected domain, endpoint, repository, version, or component.
- A concise description of the vulnerability and demonstrated security impact.
- Reproduction steps, proof-of-concept material, and any prerequisites.
- Whether you accessed any data and what you did with it.
- Your preferred contact information and, if desired, how you would like to be credited.
Please do not include secrets, unnecessary personal information, or data belonging to other people in the initial report.
6. What you can expect
We aim to acknowledge reports within five business days and provide an initial assessment or status update within ten business days. Resolution time depends on severity, complexity, affected dependencies, and the coordination required. We will make a reasonable effort to keep you informed and to coordinate any public disclosure.
7. Safe harbor
If you conduct research in good faith and make a reasonable effort to follow this policy, we will consider your research authorized under this policy and will not initiate or support legal action based solely on that compliant research. If your activity or report raises a concern that is not clearly addressed here, contact us before proceeding.
This safe-harbor statement does not authorize activity against third-party systems and cannot bind independent third parties or law-enforcement authorities.
8. Rewards and acknowledgment
AIDEFEND Labs does not currently operate a bug bounty program. Submission of a report does not create an entitlement to payment. We may acknowledge helpful researchers with their permission, but acknowledgment is not guaranteed.
9. Security contact
Report vulnerabilities to edward@aidefendlabs.com. Machine-readable contact information is also available at /.well-known/security.txt.