Security disclosure policy.
If you have identified a vulnerability in this site, in materials published by Human Intelligence, or in services we operate, we ask that you disclose it to us before any public disclosure so that we have the opportunity to investigate and remediate.
This is the coordinated vulnerability disclosure process required of every assessed organisation by GOV-10. Human Intelligence holds itself to it.
How to report
Send security reports to security@humanintel.net. Include the affected asset, the steps to reproduce, and any proof-of-concept material. If you wish to encrypt your report, write to us first and we will arrange a key.
We do not currently operate a paid bug-bounty programme. We credit researchers by name in our correspondence and, with your permission, in the release note for the fix.
What you can expect from us
- Acknowledgement
- 2 business days
- Confirmation that a named person has your report.
- Triage and severity
- 5 business days
- Validation, severity classification, and a named owner.
- Remediation — Critical
- 7 calendar days
- Or an interim mitigation plus a dated plan for the fix.
- Remediation — High
- 30 calendar days
- Tracked to closure through our change-management process.
- Remediation — Medium / Low
- 90 calendar days
- Scheduled into the ordinary release cycle.
- Status updates
- Every 14 days
- Until the report is closed or you ask us to stop.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will regard your research as authorised. We will not initiate or support legal action against you, we will not report you to law enforcement, and if a third party brings action against you for research conducted within this policy, we will make that authorisation known.
Good faith, for this purpose, means that you report promptly, that you act only against assets Human Intelligence operates, and that you observe the limits below. If you are unsure whether a particular test is in scope, ask us first — asking is always within the policy.
Limits
We ask that researchers refrain from accessing, modifying, or retaining data that does not belong to them; from degrading or interrupting service availability, including denial-of-service testing and automated scanning at volume; from social engineering of our people, customers, or suppliers; from physical intrusion; and from publicly disclosing details before remediation has shipped or 90 days have passed, whichever is sooner. Testing that requires any of these is out of scope and outside the safe harbour above.
This policy covers assets Human Intelligence operates. It does not extend to the systems of our customers, including agents under assessment; vulnerabilities found there should be reported to the operator of the agent, and we will help route a report if you tell us what you have found.