Legal · Security
Responsible disclosure
How to report a potential security vulnerability in Pythology Aegis or this website.
DRAFT STRUCTURE — AWAITING REVIEWED LEGAL TEXTThis page shows the intended structure only. It is not a legal commitment, and the final text will be published after legal review.
1. How to report
- Use the contact form with the security topic and describe the issue at a high level
- We will reply with a secure channel for technical details — please do not include exploit details in the first message
- Include how we can reach you
2. Scope
- This website and the public demonstration console
- The Aegis service and customer-edge software — scope detail to be confirmed
- Out of scope: to be confirmed (for example, social engineering and denial-of-service testing)
3. What to expect from us
- Acknowledgement and communication approach — timelines to be confirmed after review
4. Safe harbour
- Our intent is not to pursue good-faith research that follows this policy. The formal safe-harbour wording is awaiting legal review and is not yet in effect.
5. Guidelines for researchers
- Avoid privacy violations, data destruction and service disruption
- Do not access or retain data that is not yours
- Give us reasonable time to address an issue before disclosure