Legal / Responsible Disclosure

Responsible Disclosure

Guidance for reporting a suspected security issue without exposing people or systems to unnecessary risk.

Revision prepared 2026-09-13 · Draft for business and legal review

This policy is a prepared draft. The contracting legal entity, registered address, and direct privacy contact still require confirmation before this notice can be treated as final.

Report a concern safely

If you believe you have found a vulnerability affecting the GuardNex AI website or service, start with a brief description through the contact page. Request a secure reporting channel before sending sensitive evidence.

Do not submit live credentials, customer records, private keys, or exploit artifacts containing confidential information in the public contact form.

Useful information

  • The affected URL or component and the approximate time of observation.
  • A concise description of the suspected issue and its impact.
  • Minimal, non-destructive reproduction steps.
  • Relevant browser or environment details.
  • A way to contact you for clarification.

Redact personal information and secrets from screenshots and logs. Use synthetic data whenever possible.

Respect authorization and boundaries

This page does not grant permission for security testing or access to systems. Obtain explicit written authorization for any testing beyond normal, lawful use.

Do not access other people’s data, perform denial-of-service activity, use social engineering, send phishing messages, introduce malware, persist access, or test third-party services without their authorization.

Limit impact and disclosure

If you unexpectedly encounter sensitive information, stop, avoid copying or changing it, and report the issue through an appropriate channel. Preserve only the minimum evidence necessary to explain the concern.

Coordinate any public disclosure to avoid increasing risk while an issue is assessed. This page does not promise a bounty, payment, legal safe harbor, or a specific response deadline.

Follow-up

The team may request additional information to reproduce and assess the issue. Avoid sending repeated sensitive details while a secure channel is being arranged. For an issue involving a third-party product, use that provider’s reporting process.