Report a vulnerability

Send to

[email protected]

PGP not currently offered — if that's a blocker for your report, say so and we'll work something out. Machine-readable contact: /.well-known/security.txt (RFC 9116).

Please include: affected URL or repo/commit, a clear reproduction (steps, request/response, or PoC), impact assessment, and your contact info for follow-up. Reports with a working repro get triaged fastest.

What to expect

StepTiming
AcknowledgmentWithin 2 business days
Initial triage & severity callBest effort, typically within 5 business days
Fix or mitigationNo fixed SLA — severity-driven; we'll tell you our target once triaged
Coordinated disclosure window90 days from acknowledgment, or sooner by mutual agreement

This is a solo/small-maintainer project, not a funded security team with a 24/7 SOC. The 2-day acknowledgment and 90-day disclosure window are commitments we intend to keep, not aspirational marketing — we've deliberately kept them conservative rather than promising a turnaround we might miss.

Scope

  • ainumbers.co — the tool suite, ChainGraph/OCG chains and kernels, the MCP server at mcp.ainumbers.co
  • Helm — github.com/PostOakLabs/ainumbers-helm (daemon, verifier, UI, kernels)
  • Out of scope: social engineering, physical attacks, denial-of-service testing, third-party services we don't operate (GitHub, Cloudflare, DreamHost themselves)

Safe harbor

Good-faith security research conducted under this policy — without accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue, and without service disruption — will not trigger legal action from us. If in doubt about whether a test is in scope, ask first.

Coordinated disclosure & credit

We ask that you not publicly disclose a vulnerability until it's fixed or the 90-day window elapses, whichever is sooner. With your permission, we're happy to credit you in release notes or the fix commit once it ships. Confirmed vulnerabilities are published as GitHub Security Advisories on the affected repo.