Trust Center / Security

Vulnerability Disclosure Policy

Updated · View source ↗

We welcome security research and report our findings in public, minus anything that identifies a customer.

Scope

  • Hosts within *.isotope13.(io|dev|ai|net)
  • Out of scope: issues customers wouldn't care about—spam, local clickjacking, weak SSL ciphers
  • Not allowed: denial of service, social engineering

Reporting

See our security.txt.

What to Expect

  • Within 72 hours: a response, and for critical issues, a fix or mitigation
  • An invitation to co-write a blog article
  • $50 to the non-profit of your choice for a serious vulnerability with reproduction steps

Safe Harbor

We will not pursue legal action against your research. Go crazy, but don't harm customers.