Legal · Security
Responsible Disclosure
AIGR™ welcomes good-faith reports that help protect the website, governance platform, assessment workflows and client evidence. This policy describes the rules for authorized security research and coordinated reporting.
01 · Our commitment
For reports made in good faith and in accordance with this policy, AIGR™ will make reasonable efforts to acknowledge the report, assess severity, coordinate remediation and communicate when the issue has been resolved or otherwise closed.
02 · Safe-harbour intent
AIGR™ does not intend to pursue legal action against a researcher for accidental, good-faith activity that stays within this policy, avoids privacy harm, minimizes access to data and stops testing once sufficient evidence exists to demonstrate the vulnerability. This statement does not authorize activity against third-party systems and cannot bind third parties.
03 · In scope
- The public AIGR™ website and subdomains operated by the site operator.
- AIGR™ authentication, tenancy, evidence handling and authorization controls where the researcher is legitimately authorized to access the relevant environment.
- AIGR™ APIs or integrations operated by the site operator.
- Exposed credentials, secrets or configuration demonstrably belonging to AIGR™.
04 · Rules of engagement
- Use the minimum testing needed to demonstrate the issue.
- Do not access, copy, modify, delete, download or retain client evidence beyond what is strictly necessary to confirm impact.
- Do not access tenant, patient, applicant, employee, government-protected or other personal data unless unavoidable to demonstrate the issue, and stop immediately if such data is encountered.
- Do not perform denial-of-service, destructive testing, social engineering, physical attacks, credential stuffing or spam.
- Do not publicly disclose an unresolved vulnerability before reasonable time has been provided for remediation and coordinated disclosure.
- Do not demand payment or threaten disclosure as a condition of reporting.
05 · Out of scope
Reports based only on automated scanner output without demonstrated impact, missing security headers without exploitable consequence, self-XSS, low-risk rate-limiting observations, and issues affecting third-party services outside AIGR™ control may be closed without remediation. Report third-party vulnerabilities to the relevant provider.
06 · What to include
A useful report includes the affected URL or component, vulnerability type, reproduction steps, observed impact, screenshots or request/response details where safe, and a reliable way to contact the researcher. Do not include unnecessary personal information or confidential client material.
07 · Reporting
Submit a security report through the AIGR™ contact page or email [email protected] and clearly mark the subject as SECURITY — RESPONSIBLE DISCLOSURE.
08 · Client data incidents
If you are an AIGR™ client and believe your organization’s tenant, evidence or rating data may have been exposed, use the contact channel immediately and identify the matter as an urgent client-data issue. Those reports should be handled under incident-response and breach-notification procedures rather than ordinary vulnerability triage.
09 · Recognition and bounty
Unless a separate program is published, AIGR™ does not operate a paid bug bounty. Researchers may request public credit or anonymity when a valid report is resolved.
10 · Changes
This policy may be revised as the AIGR™ platform and security program evolve. Testing is governed by the version in effect when the activity occurs.