Vulnerability Disclosure Policy

Last updated: August 26, 2026

We build our business on finding vulnerabilities in AI systems, so we take reports about our own seriously. This policy explains how to report a security issue to SilverXAI, what you can expect from us in return, and the protections we extend to researchers acting in good faith.

1. Scope

This policy covers silverxai.com and its subdomains, and any service we operate that is publicly reachable from them.

Client systems we test under engagement are not covered by this policy. If you believe you have found a vulnerability in a system belonging to one of our clients, contact that organisation directly — we cannot authorise testing against infrastructure we do not own.

2. How to Report

Email security@silverxai.com. This address is also published in our machine-readable policy file at /.well-known/security.txt, in line with RFC 9116.

A useful report includes: the affected URL or endpoint, the class of issue, the steps needed to reproduce it, and an assessment of impact. Proof-of-concept code, screenshots, or request captures help us triage faster.

Please report in English where possible, and send one issue per email.

3. Our Commitment

We will acknowledge your report within 3 business days.

We will provide an initial assessment, including whether we consider the issue in scope and our expected remediation timeline, within 10 business days.

We will keep you informed as we work toward a fix, and we will tell you when the issue is resolved.

We will not pursue legal action against researchers who report in good faith and follow this policy.

4. Safe Harbour

If you make a good-faith effort to comply with this policy during your research, we will consider your activity authorised, we will not initiate or support legal action against you for it, and we will help make it known that your actions were authorised if a third party takes action.

This authorisation does not extend to activity that violates applicable law, and it does not bind third parties. You remain responsible for complying with all laws that apply to you.

5. What We Ask of You

Give us reasonable time to investigate and remediate before disclosing publicly or to any third party. We will work with you on a coordinated disclosure timeline.

Only interact with accounts you own or have explicit permission to access. Do not access, modify, or exfiltrate data belonging to others.

Stop testing and report immediately if you encounter personal data, credentials, or proprietary information.

Do not degrade the availability or integrity of our services. Automated scanning that generates significant traffic is not authorised.

Do not use social engineering, phishing, or physical intrusion against our staff, contractors, or facilities.

6. Out of Scope

The following are generally not accepted unless you can demonstrate a concrete, exploitable impact: missing security headers with no proven exploitation path; findings from automated scanners without validation; reports of outdated software versions absent a working exploit; denial of service; rate-limiting concerns on non-authenticated endpoints; email configuration issues such as SPF, DKIM, or DMARC unless actively exploitable; self-XSS; clickjacking on pages with no sensitive action; and vulnerabilities affecting only unsupported or end-of-life browsers.

Findings in third-party services we consume should be reported to that vendor. Tell us as well so we can assess our exposure.

7. Recognition

We do not currently operate a paid bug bounty programme.

With your permission, we are glad to credit you publicly once an issue is resolved. If you would rather remain anonymous, tell us and we will respect that.

8. Changes to This Policy

We may update this policy from time to time. The current version always lives at this URL and is referenced from our security.txt file.

Questions about this policy? Reach us via our contact page.