CASSI

Vulnerability Disclosure Policy

Polymorph AI is committed to ensuring the security of our customers and our platform. This policy is intended to give security researchers clear guidelines for conducting vulnerability discovery activities and to convey our preferences in how to submit discovered vulnerabilities to us.

Safe Harbor

When conducting vulnerability research according to this policy, we consider this research to be:

  • Authorized in accordance with the Computer Fraud and Abuse Act (CFAA)
  • Exempt from the Digital Millennium Copyright Act (DMCA)
  • Lawful, helpful to the overall security of the Internet, and conducted in good faith.

Guidelines

  • Notify us as soon as possible after you discover a real or potential security issue.
  • Make every effort to avoid privacy violations, degradation of user experience, disruption to production systems, and destruction or manipulation of data.
  • Only use exploits to the extent necessary to confirm a vulnerability's presence.
  • Provide us a reasonable amount of time to resolve the issue before you disclose it publicly.
Report a Vulnerability
Found a vulnerability? Let us know using the form below. Our security team will review it immediately.