Report a security issue.
If you have found a vulnerability in this website, in cortexvigil.com, or in a product deployment, we want to hear about it — directly, and before anyone else does.
Email us. That is the whole process.
No portal, no form, no bounty platform. A person reads the mailbox.
- Contact
- hello@svakrit.ai
- Subject line
Security report— so it is triaged first- Language
- English
Tell us what you found, where, and how to reproduce it. Screenshots, request/response pairs and a proof-of-concept help; a working exploit is not required. If the issue involves customer data, say so in the first line.
If you need to send something sensitive and would rather not do so in plain email, say so and we will arrange a channel.
What we commit to.
These are commitments about our conduct. They are the only promises on this page.
- Acknowledgement within 3 business days. A human reply confirming we have it, not an auto-responder.
- An assessment within 10 business days — whether we agree it is a vulnerability, how severe we think it is, and what we intend to do.
- A fix timeline proportionate to severity. Something that exposes customer data is treated as an incident, not a ticket.
- We keep you informed until it is resolved, and tell you when it is.
- Credit if you want it, once the issue is fixed. Anonymity if you prefer.
We do not currently run a paid bounty programme. If that changes, this page will say so.
Good-faith research is welcome.
We will not pursue action against researchers who follow these rules.
If you act in good faith, we will not initiate legal action against you for security research on our systems. Good faith means:
- Make a genuine effort to avoid privacy violations, data destruction, and disruption to our services or anyone else's.
- Do not access, modify or exfiltrate data that is not yours beyond the minimum needed to demonstrate the issue. If you encounter personal or customer data, stop and report.
- Give us reasonable time to fix the issue before any public disclosure.
- Do not use social engineering, physical intrusion, or denial-of-service.
- Do not test against a customer's production deployment without that customer's explicit permission.
This applies to systems we operate. It cannot extend to third parties — our hosting provider, our mail provider, or a customer's own infrastructure — whose rules are their own.
What is in, what is out.
Report anything you believe is real. This is what we consider clearly in scope.
In scope
- svakrit.ai and its hosting configuration
- cortexvigil.com
- The CortexVigil platform — its APIs, its MCP server, its edge and cloud runtime, and its tenant-isolation, authentication and authorisation controls
- Our published packages, artefacts and repositories
Out of scope
- Findings that require a compromised device or physical access
- Reports from automated scanners with no demonstrated impact
- Missing security headers on this static site that have no exploitable consequence — though we will still read them
- Third-party services we use but do not operate
What the platform enforces.
This page is about reporting to us. The platform's own security model is described where it belongs.
How the product constrains what an agent can do — limits enforced outside the model, per-tenant isolation, data that stays where it starts, an audit trail rather than a log — is set out on the platform page. Certification status, penetration-test reports and security questionnaires are handled in a technical session rather than published here; ask at hello@svakrit.ai.