AI Stays Local

Draft policy, pending legal review

Responsible disclosure

If you have found a security problem, we would rather hear it from you than read about it later. This page says how to tell us and what we will do.

How to report

Write to security@aistayslocal.com. Include enough detail to reproduce the issue: the URL or component, the steps, and what you observed. If you have a proof of concept, describe it rather than attaching anything executable.

What we commit to

We will acknowledge your report within five working days, keep you informed while we investigate, and tell you when it is fixed. We will credit you publicly if you want that and stay quiet about you if you do not. We will not take legal action against someone who followed this policy in good faith.

We are one small team without a bug bounty programme, so there is no payment. We will say so up front rather than leaving you to discover it after the work.

In scope

This website and its infrastructure, on aistayslocal.com and its subdomains. Once a beta build exists, the desktop application and its update mechanism as well - this page will be updated when that happens.

Out of scope

Denial of service, volumetric or automated scanning that degrades the service for others, social engineering of any person, physical attacks, and reports generated by a scanner without a demonstrated impact. Please do not test against anyone else’s data, and do not access, modify or retain data that is not yours.

Disclosure

We ask for ninety days before public disclosure, and we will usually be faster than that. If we disagree about severity or timing we will tell you why, in writing, rather than going quiet.

This is a draft policy written by the product team. It has not been reviewed by a lawyer, and the safe harbour wording above in particular needs that review before it can be relied on.

Prelaunch. The desktop application is in development and the private beta has not opened yet.