Security
Responsible disclosure
We are building a system whose entire value is that it can be trusted. If you find a weakness in it, we want to hear from you first.
Last updated: 16 August 2026
How to report
Email security@aiutotech.ai. Include the affected URL or component, the steps to reproduce, and what impact you believe it has. Please do not publish details before we have responded.
Machine-readable contact details are published at /.well-known/security.txt.
Our commitment to you
We will not pursue legal action, and will not ask others to, against anyone who reports a vulnerability in good faith, stays within the scope below and gives us reasonable time to fix it. We will credit you if you would like us to.
Scope and ground rules
- In scope: aiutotech.ai and its subdomains.
- Do not access, modify or exfiltrate data that is not your own.
- No denial-of-service, spam, social engineering or physical attacks.
- Use test accounts and stop as soon as you have confirmed the issue.
Response times
- Acknowledgement: within 3 business days.
- Initial assessment and severity: within 10 business days.
- Fix or a dated remediation plan: within 90 days, and sooner for critical issues.