Security

Responsible disclosure acknowledgments.

We thank everyone who practices coordinated disclosure. Reporters listed here agreed to be named. To report a vulnerability, follow the process at /.well-known/security.txt.

Hall of recognition

No public disclosures have been credited yet. When we receive a valid report and the reporter consents to acknowledgment, they will appear here.

How to report

  1. Send a short initial report without sensitive material. Arrange a suitable channel for any additional details.
  2. Email [email protected] with a clear subject line and reproducible steps.
  3. Acknowledgment within 24 hours. Triage within 5 business days.
  4. Coordinated disclosure preferred — we will credit you here by name (or alias) if you consent.

Full policy: /.well-known/security.txt (RFC 9116)

Scope

  • In scope: morvs.ai, ai-analytics.org, and api.ai-analytics.org.
  • Separate operator: Voidly and its GitHub repositories are operated independently and are not covered by this MORVS policy.
  • Out of scope: Social engineering, physical security, DoS/DDoS, issues in third-party dependencies already reported upstream.
  • Safe harbor: AI Analytics LLC will not pursue legal action for good-faith research on the in-scope assets that follows this policy.