Responsible Vulnerability Disclosure

Introduction

At DeepTrust AI, we take the security of our platform and customer data seriously. We recognize the important role that independent security researchers and the community play in identifying vulnerabilities. If you discover a potential issue, we ask that you help us protect our users by following this Responsible Vulnerability Disclosure Policy.

  • By reporting security concerns responsibly, you are helping us maintain the trust and safety of our customers and their data.

How to Report a Vulnerability

If you believe you have found a security vulnerability in DeepTrust AI:

  • Email us at: [email protected]
  • Include as much detail as possible, including:
  • Steps to reproduce the issue
  • The affected system or feature
  • Any proof-of-concept code, if applicable
  • Your contact information so we can follow up

What to Avoid

To protect our customers and systems, please:

  • Do not attempt to access, modify, or delete data that does not belong to you.
  • Do not use automated scanners that generate significant traffic or impact service availability.
  • Do not conduct denial-of-service (DoS) attacks, social engineering, or phishing against our employees, contractors, or customers.
  • Do not publicly disclose details of the vulnerability until we have confirmed and remediated the issue.

Our Commitment to You

When you report a vulnerability in good faith and in compliance with this policy:

  • We will acknowledge receipt of your report within 72 hours.
  • We will investigate and validate the issue as quickly as possible.
  • We will keep you informed of our progress and the status of your report.
  • Once resolved, we may credit you for the discovery if you wish to be recognized.
  • We will not pursue legal action against researchers who follow this policy.

Safe Harbor

DeepTrust AI commits to:

  • Not initiating legal action against security researchers who act in good faith and comply with this policy.
  • Considering security research conducted under this policy as authorized access under applicable anti-hacking laws.
  • Treating research findings as confidential until both parties agree that disclosure is safe.

Scope

This policy applies to:

  • DeepTrust AI web applications hosted under deeptrust.ai.
  • DeepTrust AI APIs and related services.
  • Mobile apps (when applicable).

Out of scope:

  • Third-party services or platforms not owned by DeepTrust AI (though we encourage responsible disclosure directly to those vendors).
  • Physical attacks against DeepTrust AI offices or employees.
  • Social engineering of DeepTrust AI staff, contractors, or customers.

Recognition

We appreciate the efforts of security researchers who help us improve. While we do not currently offer a paid bug bounty program, we may recognize valid submissions on our website or in release notes, with your permission.

Bug Bounty Roadmap

Introduction

At DeepTrust AI, security is fundamental to trust. While we currently operate a Responsible Vulnerability Disclosure Program, we recognize the value of evolving this into a formal Bug Bounty Program to further engage the global security research community.

  • Our roadmap ensures that as we grow, we continue to meet the highest standards of security and accountability.

Current Phase: Responsible Disclosure

  • Vulnerabilities can be reported to [email protected].
  • We acknowledge reports within 72 hours.
  • Valid issues are prioritized, investigated, and remediated quickly.
  • Safe Harbor protection applies to all researchers who act in good faith.
  • Recognition may be offered on our website or in release notes.

Next Phase: Private Pilot Bug Bounty Program (Planned)

We plan to launch an invite-only bug bounty program with trusted security researchers.

  • Participants will receive structured scope documentation.
  • Valid submissions may be eligible for monetary rewards.
  • The pilot will help us refine severity ratings, triage processes, and payout structures.

Future Phase: Public Bug Bounty Program (Long-Term Goal)

Once the private program is mature, we intend to open the DeepTrust AI Bug Bounty Program to the broader research community.

  • Public scope will include apps, APIs, and integrations.
  • Reward tiers will be based on severity and impact.
  • Transparency reports will be published annually, highlighting issues discovered and resolved.

Timeline

  • 2025: Responsible Disclosure live (current phase).
  • 2026: Launch Private Bug Bounty Pilot (invite-only).
  • 2027: Expand to a Public Bug Bounty Program.
  • These dates may evolve as we scale, but security will remain central to our roadmap.

Researcher Recognition

We deeply value the contributions of ethical security researchers. As our Bug Bounty Program evolves, we will create:

  • Hall of Fame: Public recognition of top contributors (opt-in).
  • Reward System: Monetary compensation tied to severity ratings (CVSS-based).
  • Community Engagement: Ongoing collaboration with researchers worldwide.

Questions?

If you'd like to be considered for the private pilot program, or if you have questions about our roadmap, please contact:

For questions about this document, contact [email protected]