Trust Center / Security
Vulnerability Disclosure Policy
We welcome security research and report our findings in public, minus anything that identifies a customer.
Scope
- Hosts within
*.isotope13.(io|dev|ai|net) - Out of scope: issues customers wouldn't care about—spam, local clickjacking, weak SSL ciphers
- Not allowed: denial of service, social engineering
Reporting
See our security.txt.
What to Expect
- Within 72 hours: a response, and for critical issues, a fix or mitigation
- An invitation to co-write a blog article
- $50 to the non-profit of your choice for a serious vulnerability with reproduction steps
Safe Harbor
We will not pursue legal action against your research. Go crazy, but don't harm customers.