Security
Responsible disclosure
If you have found a security vulnerability affecting AuthTechAI, we want to hear about it. This page sets out how to report it and what happens next.
How to report
Email connect@authtechai.com with “Security” in the subject line. Please include the affected URL or endpoint, steps to reproduce, and what impact you believe it has. A short proof of concept helps us triage faster than a scanner export.
Our machine-readable contact details are published at /.well-known/security.txt.
What we ask of you
- Give us reasonable time to remediate before disclosing publicly.
- Do not access, modify or delete data that is not yours.
- Do not degrade the service for anyone else.
- Do not test our clients' systems under this policy - it does not cover them.
What you can expect from us
- Acknowledgement
- Within 3 working days of your report
- Initial assessment
- Within 10 working days
- Progress updates
- At least every 15 working days until resolved
- Credit
- With your permission, in our disclosure acknowledgements
We will not pursue legal action against researchers who follow this policy in good faith.
In scope
- authtechai.com and its subdomains
- Our published web application and its API endpoints
- Our email and DNS configuration
Out of scope
- Systems belonging to our clients - report those to the client directly
- Findings from automated scanners without a demonstrated impact
- Social engineering of our staff, suppliers or clients
- Denial of service, volumetric or resource-exhaustion testing
- Missing security headers or best-practice recommendations with no exploit path
- Reports about software we neither operate nor supply
We do not currently operate a paid bug bounty. Reports are handled on the terms above.

