Responsible Disclosure
We welcome reports of security vulnerabilities and commit to working with the security community in good faith. If you find a vulnerability, please report it to us so we can fix it before it harms users.
How to report
Email security@sensemakingwith.ai with:
- A clear description of the vulnerability.
- Steps to reproduce it (URLs, parameters, payloads).
- The impact you've observed or believe is possible.
- Optionally, a suggested fix.
For sensitive reports, you may encrypt your email to our PGP key (fingerprint to be published before launch).
Our commitments
- Acknowledgement within 3 business days.
- Initial triage within 7 business days.
- Status updates at least every 14 days until resolution.
- We will not pursue legal action against good-faith researchers who comply with this policy.
- We will credit you in our security advisory, with your permission.
Scope
In scope: sensemakingwith.ai and any subdomain we operate. Vulnerabilities in our authentication, authorization, data handling, or third-party integrations.
Out of scope:
- Findings from automated scanners with no demonstrated impact.
- Self-XSS or rate-limiting on individual users.
- Best-practice missing-headers reports without an exploit chain.
- Vulnerabilities in third-party services we depend on (report those upstream).
- Social engineering, physical attacks, or denial-of-service.
Researcher conduct
We ask that you:
- Test only against accounts you own; do not access, modify, or delete data belonging to other users.
- Avoid tactics that could degrade service availability for other users (e.g., aggressive scanning).
- Give us reasonable time to fix the issue before public disclosure (typically 90 days).
- Do not exploit findings beyond what's necessary to demonstrate the issue.
Bug bounty
We do not currently operate a paid bounty program but may award discretionary bounties for high-impact reports. We are evaluating a formal program.