Vulnerability Disclosure Policy
Effective October 4, 2026 · Last updated October 4, 2026
If you find a security vulnerability in Promigence, we want to hear about it. This policy explains how to report it and the rules that keep your research authorized.
How to report#
Email support@promigence.ai with "security" in the subject line and enough detail for us to reproduce the issue. Keep it private until we have fixed it or agreed a disclosure date with you. Our contact details are also published at www.promigence.ai/.well-known/security.txt.
Rules#
- Test only against accounts and sandboxes you own.
- Do not test or access other customers' accounts, sandboxes or data, or our providers' systems.
- Do not copy, keep, change or delete data that is not yours. If you reach any, stop, tell us, and delete what you obtained.
- Do not run denial-of-service, load or high-volume automated tests, and do not use social engineering, phishing or physical attacks.
- Use a vulnerability only as far as needed to show that it exists.
Safe harbor#
If you follow these rules in good faith, we will treat your research as authorized, and we will not take legal action against you, or ask law enforcement to investigate you, for that research. This applies only to systems owned by Promigence AI, Inc.; we cannot authorize tests of anyone else's systems.
Rewards#
We plan to start a bug bounty program as we grow, and we'll announce it on this page when we do. Until then, you have our sincere thanks, and if you'd like, we'll gladly thank you publicly. A report that comes with a demand for payment is outside this policy.
Everything else#
All other use of Promigence remains subject to our Terms of Service and Acceptable Use Policy.