Skip to content
AEI Labs

Responsible disclosure

Report security concerns safely.

This page reserves the disclosure route. It must not go live until a monitored security mailbox, response owner and policy scope are in place.

Security mailbox and SLA pending

Vulnerability disclosure guidance.

What to include

The affected URL or product, reproduction steps, potential impact and any supporting evidence. Avoid including unnecessary personal or confidential data.

Good-faith testing

The final policy must define permitted testing, prohibited activity, safe-harbour language, scope and how AEI Labs will coordinate disclosure.

Do not proceed yet

Do not disrupt services, access other users’ data, use social engineering or retain data beyond what is needed to demonstrate an issue.

Contact route

Replace this text with the monitored security address and an acknowledgement target before publication.