Responsible Disclosure
If you have found a security vulnerability in an AIGX Research™ system, we want to hear about it. This policy sets out how to report one and what we commit to in return.
01Our commitment
We hold governance evidence on behalf of organizations in regulated sectors. The security of that material is not a secondary concern for us, and we treat external reports as a valued part of how we protect it.
If you report a vulnerability in good faith under this policy, we commit to:
- Acknowledge your report within 3 business days
- Provide an initial assessment and severity rating within 10 business days
- Keep you informed of remediation progress at reasonable intervals
- Notify you when the issue is resolved
- Credit you publicly if you wish, or keep your report confidential if you prefer
- Not pursue or support legal action against you
02Safe harbour
We will not initiate or support legal action against researchers who, in good faith, discover and report a vulnerability in accordance with this policy. We consider such activity authorized under applicable computer misuse and anti-circumvention laws, and we will not treat it as a breach of our Terms of Use.
This protection applies as long as you follow the rules of engagement in section 4 and do not access, alter, destroy or exfiltrate data belonging to us or to our clients beyond the minimum necessary to demonstrate the issue.
If a third party brings action against you for activity conducted under this policy, we will make it known that your activity was authorized.
03Scope
In scope
aigx.caand its subdomains- The AIGX governance platform and its authentication, tenancy and evidence handling
- APIs and integrations operated by AIGX
- Email and DNS configuration under our control, including SPF, DKIM and DMARC
- Exposed credentials, keys or configuration belonging to AIGX
Out of scope
- Third-party services we do not control — report those to the vendor
- Findings from automated scanners without a demonstrated, exploitable impact
- Missing security headers, cookie flags or TLS configuration with no practical exploit path
- Social engineering, phishing or physical attacks against our staff, clients or offices
- Denial of service, volumetric or resource-exhaustion testing
- Self-XSS, clickjacking on pages with no sensitive action, and version-disclosure banners
- Vulnerabilities requiring a rooted or compromised device, or a fully man-in-the-middle position
04Rules of engagement
To stay within this policy:
- Access only data that belongs to you or to a test account you control
- Stop as soon as you have confirmed a vulnerability — do not pivot further into the environment
- Do not access, modify, delete or retain any client evidence, personal information or health information
- If you encounter such data accidentally, stop, do not save a copy, and tell us immediately
- Do not degrade service for others, and do not run high-volume automated testing
- Do not publish details before we have remediated, or before the disclosure timeline in section 6 has elapsed
- Do not demand payment in exchange for withholding a report
05How to report
Email [email protected] with SECURITY at the start of the subject line. Please include as much of the following as you can:
| Field | What to provide |
|---|---|
| Summary | One or two sentences on the issue and its impact |
| Affected asset | URL, endpoint, hostname or component |
| Reproduction | Clear, ordered steps; requests and responses where relevant |
| Impact | What an attacker could realistically achieve |
| Evidence | Screenshots or logs, with any sensitive data redacted |
| Your details | How to reach you, and how you would like to be credited |
Reports in English are preferred. If your report contains sensitive material, ask us for an encryption key before sending it.
06Disclosure timeline
We ask for 90 days from acknowledgement before public disclosure, and we will usually remediate well within that. If we need longer for a complex issue, we will explain why and agree a revised date with you rather than let it lapse silently.
We are happy to coordinate a joint disclosure, and we will not ask you to stay quiet indefinitely.
07Recognition
We do not currently operate a paid bug bounty. We offer written acknowledgement, credit in our security advisories where you want it, and a direct line to our engineering team for future reports.
If you would prefer to remain anonymous, say so and we will not name you.
08Client-reported issues
If you are an AIGX client and believe your tenant, evidence or rating data has been exposed, contact [email protected] and mark the subject line URGENT — CLIENT DATA. Those reports are escalated immediately and handled under our incident response and breach notification procedures rather than this policy.
Notice
© 2026 AIGX Research™. This policy describes how AIGX handles externally reported security vulnerabilities. It does not grant any licence to AIGX intellectual property beyond the testing activity described, and does not vary the AIGX Terms of Use except as expressly stated in section 2.