Responsible Disclosure
How to report a security vulnerability in the SecAI Solutions website.
Last updated:
We take the security of this website seriously and welcome reports from the security community.
How to report
Email security@secaisolutions.com with:
- A description of the issue and its potential impact
- Clear steps to reproduce, including any required accounts or payloads
- Any supporting evidence — request/response pairs, screenshots, proof-of-concept
- How you would like to be credited, if at all
A machine-readable version of this policy is published at /.well-known/security.txt.
What we commit to
- Acknowledgement within 3 business days
- An initial assessment within 10 business days
- Regular updates while we investigate and remediate
- Public credit where you want it, once the issue is resolved
Scope
In scope: the website at secaisolutions.com and its subdomains, and the contact form endpoint.
Out of scope:
- Denial-of-service, volumetric or stress testing of any kind
- Social engineering of our team, clients or service providers
- Physical attacks against any premises
- Findings from automated scanners without a demonstrated impact
- Reports about missing headers or configuration hardening with no exploitable consequence
- Third-party services we do not operate
- Any testing that accesses, modifies or destroys data belonging to others
Safe harbour
If you make a good-faith effort to comply with this policy, we will not pursue legal action in relation to your research. Please act in good faith: stay within scope, avoid privacy violations and service degradation, use only your own test data, and give us reasonable time to remediate before any public disclosure.
Please do not
- Access, modify or exfiltrate data that is not yours
- Run destructive tests or attempt to degrade availability
- Publish details of an unresolved issue
Last updated: 21 September 2026