Security
Responsible disclosure acknowledgments.
We thank everyone who practices coordinated disclosure. Reporters listed here agreed to be named. To report a vulnerability, follow the process at /.well-known/security.txt.
Hall of recognition
No public disclosures have been credited yet. When we receive a valid report and the reporter consents to acknowledgment, they will appear here.
How to report
- Send a short initial report without sensitive material. Arrange a suitable channel for any additional details.
- Email [email protected] with a clear subject line and reproducible steps.
- Acknowledgment within 24 hours. Triage within 5 business days.
- Coordinated disclosure preferred — we will credit you here by name (or alias) if you consent.
Full policy: /.well-known/security.txt (RFC 9116)
Scope
- In scope: morvs.ai, ai-analytics.org, and api.ai-analytics.org.
- Separate operator: Voidly and its GitHub repositories are operated independently and are not covered by this MORVS policy.
- Out of scope: Social engineering, physical security, DoS/DDoS, issues in third-party dependencies already reported upstream.
- Safe harbor: AI Analytics LLC will not pursue legal action for good-faith research on the in-scope assets that follows this policy.