Skip to content

Security

Responsible disclosure

If you have found a security vulnerability affecting AuthTechAI, we want to hear about it. This page sets out how to report it and what happens next.

How to report

Email connect@authtechai.com with “Security” in the subject line. Please include the affected URL or endpoint, steps to reproduce, and what impact you believe it has. A short proof of concept helps us triage faster than a scanner export.

Our machine-readable contact details are published at /.well-known/security.txt.

What we ask of you

  • Give us reasonable time to remediate before disclosing publicly.
  • Do not access, modify or delete data that is not yours.
  • Do not degrade the service for anyone else.
  • Do not test our clients' systems under this policy - it does not cover them.

What you can expect from us

Acknowledgement
Within 3 working days of your report
Initial assessment
Within 10 working days
Progress updates
At least every 15 working days until resolved
Credit
With your permission, in our disclosure acknowledgements

We will not pursue legal action against researchers who follow this policy in good faith.

In scope

  • authtechai.com and its subdomains
  • Our published web application and its API endpoints
  • Our email and DNS configuration

Out of scope

  • Systems belonging to our clients - report those to the client directly
  • Findings from automated scanners without a demonstrated impact
  • Social engineering of our staff, suppliers or clients
  • Denial of service, volumetric or resource-exhaustion testing
  • Missing security headers or best-practice recommendations with no exploit path
  • Reports about software we neither operate nor supply

We do not currently operate a paid bug bounty. Reports are handled on the terms above.