Security

Responsible disclosure

If you believe you have found a security vulnerability in a mAIb Tech product or website, we want to hear from you — and we will treat a good-faith report as help, not hostility.

How to report

Email support@maib.io with "Security" in the subject line and a clear description. We currently do not publish a PGP key; do not include exploit payloads for critical findings in plain email — describe the issue and we will arrange a secure channel.

What to include

  • The affected product, domain or endpoint
  • Steps to reproduce, or a proof-of-concept description
  • The impact you believe the issue has
  • Your contact details for follow-up (anonymous reports are accepted)

Scope

  • maib.io and its subdomains (locs.maib.io, gaio.maib.io, hir.maib.io, ai4ai.maib.io, ipmp.maib.io, tools.maib.io)
  • mAIb Tech software products, including evaluation deployments you are authorised to test

Please do not

  • Test systems you are not authorised to access, including customer deployments
  • Run denial-of-service, spam or social-engineering attacks
  • Access, modify or exfiltrate data that is not yours; if you encounter such data, stop and report
  • Publicly disclose an issue before we have had a reasonable opportunity to address it

What you can expect from us

  • Acknowledgement of your report, normally within 5 business days
  • An assessment and remediation plan communicated to you
  • Credit for the finding if you want it, once resolved

Safe harbour

We will not pursue legal action against good-faith security research that respects the constraints above. This statement reflects our intent and is subject to applicable law; it is not a contract.

Bug bounty

We do not currently operate a paid bug-bounty programme, and we do not promise rewards. If that changes, terms will be published here.