Vulnerability disclosure policy
Found a security issue? Tell us.
AINumbers.co and Helm are maintained by a small team. This page is our honest, plain-English commitment on how reports are handled — no vendor-portal theater, no promises we can't keep.
Report a vulnerability
Send to
[email protected]PGP not currently offered — if that's a blocker for your report, say so and we'll work something out. Machine-readable contact: /.well-known/security.txt (RFC 9116).
Please include: affected URL or repo/commit, a clear reproduction (steps, request/response, or PoC), impact assessment, and your contact info for follow-up. Reports with a working repro get triaged fastest.
What to expect
| Step | Timing |
|---|---|
| Acknowledgment | Within 2 business days |
| Initial triage & severity call | Best effort, typically within 5 business days |
| Fix or mitigation | No fixed SLA — severity-driven; we'll tell you our target once triaged |
| Coordinated disclosure window | 90 days from acknowledgment, or sooner by mutual agreement |
This is a solo/small-maintainer project, not a funded security team with a 24/7 SOC. The 2-day acknowledgment and 90-day disclosure window are commitments we intend to keep, not aspirational marketing — we've deliberately kept them conservative rather than promising a turnaround we might miss.
Scope
- ainumbers.co — the tool suite, ChainGraph/OCG chains and kernels, the MCP server at mcp.ainumbers.co
- Helm — github.com/PostOakLabs/ainumbers-helm (daemon, verifier, UI, kernels)
- Out of scope: social engineering, physical attacks, denial-of-service testing, third-party services we don't operate (GitHub, Cloudflare, DreamHost themselves)
Safe harbor
Good-faith security research conducted under this policy — without accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue, and without service disruption — will not trigger legal action from us. If in doubt about whether a test is in scope, ask first.
Coordinated disclosure & credit
We ask that you not publicly disclose a vulnerability until it's fixed or the 90-day window elapses, whichever is sooner. With your permission, we're happy to credit you in release notes or the fix commit once it ships. Confirmed vulnerabilities are published as GitHub Security Advisories on the affected repo.