Responsible disclosure
If you believe you have found a security vulnerability in a mAIb Tech product or website, we want to hear from you — and we will treat a good-faith report as help, not hostility.
How to report
Email support@maib.io with "Security" in the subject line and a clear description. We currently do not publish a PGP key; do not include exploit payloads for critical findings in plain email — describe the issue and we will arrange a secure channel.
What to include
- The affected product, domain or endpoint
- Steps to reproduce, or a proof-of-concept description
- The impact you believe the issue has
- Your contact details for follow-up (anonymous reports are accepted)
Scope
- maib.io and its subdomains (locs.maib.io, gaio.maib.io, hir.maib.io, ai4ai.maib.io, ipmp.maib.io, tools.maib.io)
- mAIb Tech software products, including evaluation deployments you are authorised to test
Please do not
- Test systems you are not authorised to access, including customer deployments
- Run denial-of-service, spam or social-engineering attacks
- Access, modify or exfiltrate data that is not yours; if you encounter such data, stop and report
- Publicly disclose an issue before we have had a reasonable opportunity to address it
What you can expect from us
- Acknowledgement of your report, normally within 5 business days
- An assessment and remediation plan communicated to you
- Credit for the finding if you want it, once resolved
Safe harbour
We will not pursue legal action against good-faith security research that respects the constraints above. This statement reflects our intent and is subject to applicable law; it is not a contract.
Bug bounty
We do not currently operate a paid bug-bounty programme, and we do not promise rewards. If that changes, terms will be published here.