Security
Report vulnerabilities responsibly.
This policy defines authorized good-faith research for our public website and a private path for reporting findings.
Scope
Know what is—and is not—authorized.
Authorization is limited to the public website expressly listed below. Contact us before testing when scope is uncertain.
01
Purpose
Spacetime Security welcomes reports that help us protect the public website and its visitors. This policy explains which systems and research activities we authorize, how to report a suspected vulnerability privately, and what researchers can expect when acting in good faith.
02
In scope
This policy applies only to the public website and web resources served from https://spacetimesecurity.ai. A service is in scope only when it is operated by Spacetime and is expressly identified here. If you are unsure whether a system is in scope, contact us before testing.
03
Out of scope
Customer environments; Spacetime products, agents, control-plane or hosted services; employee or internal systems; third-party services, infrastructure, repositories, applications, and integrations; and any other domain or asset not expressly identified above are out of scope. A separate written authorization is required before testing them.
Research boundaries
Use the minimum activity necessary.
04
Good-faith research
Research is authorized under this policy only when it is conducted solely to identify and report a security vulnerability, uses the minimum activity necessary to confirm the issue, avoids harm to people and systems, preserves privacy, complies with applicable law, and follows every boundary in this policy.
05
Permitted activity
You may inspect public responses and client-side resources, submit ordinary requests to public endpoints, and perform low-volume testing reasonably necessary to demonstrate a suspected vulnerability. Use accounts and data you own or are expressly authorized to use. Prefer a minimal proof of concept over extraction, persistence, or repeated exploitation.
06
Prohibited activity
Do not perform denial-of-service or resource-exhaustion testing; social engineering, phishing, spam, or physical attacks; password spraying or credential stuffing; malware deployment; persistence or lateral movement; destructive testing; supply-chain attacks; privacy invasion; accessing another person’s account or data; changing or deleting data; exfiltrating data; disrupting service; or testing an out-of-scope system.
07
Sensitive data
If you encounter personal information, credentials, secrets, customer information, or other sensitive data, stop testing immediately. Do not copy, retain, download, transmit, alter, or disclose it beyond the minimum evidence necessary to identify the issue. Tell us what you encountered and securely delete any inadvertently retained data after we confirm it is no longer needed.
Reporting
Send a useful report privately.
08
How to report
Email security@spacetimesecurity.ai with the affected URL or asset, vulnerability type, concise impact, reproducible steps, and a minimal proof of concept. Include the date and time of testing and any identifiers needed to locate relevant requests. Do not send live credentials, unnecessary personal data, regulated records, or exploit code that causes harm.
09
Our process
We will review reports and may contact you for clarification, validation, or coordination. Response and remediation timing depend on severity, complexity, affected parties, and operational risk. This policy does not promise an acknowledgment deadline, remediation date, status cadence, or particular outcome.
10
Coordinated disclosure
Keep the report and vulnerability confidential while we investigate and address risk. Before public disclosure, coordinate timing and content with us and allow a reasonable opportunity for validation and remediation. We may need to involve affected providers or customers. We do not require indefinite silence, but uncoordinated disclosure may increase risk and fall outside this policy.
Coordination
Good faith has defined boundaries.
11
Safe-harbor posture
When you make a good-faith effort to comply with this policy, Spacetime will consider your research authorized under this policy and will not initiate legal action against you solely for that research. If a third party initiates legal action, we may state that your activity complied with this policy. We cannot authorize activity on third-party systems, bind third parties or law-enforcement authorities, or excuse violations of law.
12
No bounty or employment promise
This is a vulnerability disclosure program, not a bug-bounty program. We do not promise payment, reward, public recognition, employment, services, or other compensation. Do not incur costs in expectation of reimbursement. Any recognition or reward is entirely discretionary and requires separate written approval.
13
Changes and questions
We may update this policy as our public systems and disclosure process change. The version posted here applies prospectively from its effective date. Questions about scope or permitted testing should be sent to security@spacetimesecurity.ai before testing begins.
Found a website vulnerability?
Send a private report with minimal evidence. Do not include unnecessary sensitive data.
Email the security team →