Legal · Security

Responsible disclosure

How to report a potential security vulnerability in Pythology Aegis or this website.

DRAFT STRUCTURE — AWAITING REVIEWED LEGAL TEXT

This page shows the intended structure only. It is not a legal commitment, and the final text will be published after legal review.

1. How to report

  • Use the contact form with the security topic and describe the issue at a high level
  • We will reply with a secure channel for technical details — please do not include exploit details in the first message
  • Include how we can reach you

2. Scope

  • This website and the public demonstration console
  • The Aegis service and customer-edge software — scope detail to be confirmed
  • Out of scope: to be confirmed (for example, social engineering and denial-of-service testing)

3. What to expect from us

  • Acknowledgement and communication approach — timelines to be confirmed after review

4. Safe harbour

  • Our intent is not to pursue good-faith research that follows this policy. The formal safe-harbour wording is awaiting legal review and is not yet in effect.

5. Guidelines for researchers

  • Avoid privacy violations, data destruction and service disruption
  • Do not access or retain data that is not yours
  • Give us reasonable time to address an issue before disclosure

Report via the contact form