Vulnerability disclosure Draft

Report a security problem.

If you have found a vulnerability in Neoteric's website or in Autom, this page explains what is in scope, how to tell us, what happens next, and the protection we offer researchers who follow it.

This page is not finished.

This policy is not final. The security mailbox, every response time, and the safe harbour wording still need to be confirmed, and the safe harbour section has not been reviewed by a lawyer. Treat the timings as unset rather than assumed, and read the safe harbour section as a statement of intent until that review has happened.

Scope

What is in scope

This website at neotericai.app, the pages it serves, and the endpoints it exposes, including the Contact Sales endpoint.

The response headers and content security policy this site serves, where you can demonstrate an impact rather than only a missing directive.

The full list of in-scope domains and services is at [[IN_SCOPE_ASSETS]]. If an asset is not listed there and is not this website, assume it is out of scope and ask before testing.

The Autom desktop application is not downloadable yet, so there is no released build to test. Released builds come into scope when downloads open.

What is out of scope

Anything not operated by Neoteric. That includes third-party language model providers, hosting and edge platforms, and any service a customer connects to Autom. Report those to the organisation that runs them.

Findings that need an already-compromised device, a privileged position on the network, or physical access to a machine.

Missing hardening headers, weak cipher suites, or configuration observations with no demonstrated impact, and scanner output submitted without a working proof of concept.

Social engineering of staff, customers, or suppliers, and anything targeting physical premises.

We already publish the known weakness in our content security policy: the script source allows inline scripts because the framework requires it to hydrate. A report that only restates that is not a new finding. A working injection that uses it is, and we want to see it.

Reporting

How to report

Send the report to [[SECURITY_CONTACT_EMAIL]]. Once that mailbox is provisioned it will also be published in an RFC 9116 security.txt file under /.well-known.

If you want to encrypt the report, the key is at [[SECURITY_PGP_KEY]].

Tell us what you found, where you found it, the exact steps to reproduce it, and what an attacker could do with it. A short proof of concept helps. A video on its own usually does not.

Report one issue per message, in English, and include a way to reach you.

Do not include another person's data in the report. If you came across some, say that you did and describe it without copying it.

What you can expect from us

We will acknowledge your report within [[ACKNOWLEDGEMENT_TIME]] and give you a first assessment within [[TRIAGE_TIME]].

While the issue is open we will update you at least every [[STATUS_UPDATE_INTERVAL]]. We will tell you when it is fixed, and we will tell you if we decide not to fix it and why.

Remediation targets by severity are at [[REMEDIATION_TARGETS]].

Those are placeholders. Until they carry real values we are not making a timing promise, and you should not read one into this page.

Rules and protection

Safe harbour

If you follow this policy, we will treat your research as authorised, we will not bring a claim against you for it, and we will not refer you to law enforcement for it.

If a third party brings a claim about research you carried out in line with this policy, we will make it known that the activity was authorised by us.

This protection covers only systems Neoteric operates, and only research that stays inside the rules below. It cannot waive anyone else's rights, and it cannot override the law of [[GOVERNING_LAW_JURISDICTION]].

The Acceptable Use Policy tells customers not to probe or test the service without a written testing agreement. For the assets listed above, and for research that follows this policy, this page is that authorisation. The two documents need to be brought into line with each other, and that is our job rather than yours.

This section has not yet been reviewed by a lawyer. Until it has, read it as a statement of how we intend to behave rather than as a legal guarantee.

If you are unsure whether something is permitted, ask at [[SECURITY_CONTACT_EMAIL]] before you do it. We would rather answer a question than argue about a test afterwards.

What not to do

Do not run denial of service tests, load tests, or anything else that degrades the service for other people.

Do not social engineer or phish our staff, our customers, or our suppliers.

Do not access, change, or delete data belonging to anyone else. If you can prove access, stop at the proof.

Do not exfiltrate data. Do not download, copy, or keep anything you find. Delete any copy as soon as it is no longer needed to demonstrate the issue, and tell us that you have.

Do not attempt physical access to premises or hardware.

Do not run automated scanning at a volume that affects availability.

Do not make a report conditional on payment. That is extortion, not disclosure, and it ends the safe harbour immediately.

Do not publish before the disclosure terms below have been met.

Disclosure

We prefer coordinated disclosure. Please give us [[DISCLOSURE_WINDOW]] from the date of your report before publishing anything about it.

If we need longer than that, we will tell you why and propose a date rather than going quiet. If we cannot fix an issue, we will say so and agree a position with you.

We will not ask you to stay silent indefinitely.

Recognition

Whether Neoteric offers any reward for a report is at [[BOUNTY_POSITION]]. Nothing on this page should be read as a promise of payment.

We are glad to credit you by name once an issue is fixed, if that is what you want. Tell us how you would like to be named. We will not publish your name without your agreement.

Where acknowledgements will be listed is at [[RECOGNITION_PAGE]]. No such page exists today.

About this policy

This policy is published by [[LEGAL_ENTITY_NAME]]. It does not create a contract between us.

We may update it. The version that applies to your report is the one published on this page at the time you send it.

Related pages

The security page lists what is implemented on this site and what is still open. If your question is commercial rather than technical, Contact Sales is the route.

Acceptable Use Policy, including the rules on security testing