Security and responsible disclosure
Last updated September 2026
Scope
This policy covers aitrace.org, platform.aitrace.org, and the AI Trace browser extension. If you find a problem in a service run by someone else, please report it to that provider.
How to report
Email security@aitrace.org. Include the page address or feature affected, the steps to reproduce the problem, what you observed, and how we can reach you if you want a reply. Anonymous reports are welcome. Please do not send us personal information about other people.
The same contact is published in machine-readable form at /.well-known/security.txt.
What to expect
We will acknowledge your report within five business days and keep you informed while we investigate and fix the problem. We do not run a bug bounty program and do not pay for reports. With your permission, we will credit you once the issue is resolved. We ask that you give us a reasonable amount of time to fix a problem before you describe it publicly.
Safe harbor
We will not take legal action against you, or refer you to law enforcement, for security research carried out in good faith. Good faith means you:
- only access accounts and data that belong to you, or that you have permission to use;
- avoid violating anyone’s privacy, destroying data, or disrupting the service for other people;
- stop and report as soon as you confirm a vulnerability, rather than exploring further; and
- do not use a vulnerability for any purpose other than demonstrating it to us.
We consider research that follows these rules to be authorized, and we will not treat it as a violation of our terms of use. If you are unsure whether something is in bounds, ask us first at the address above.