Vulnerability Disclosure Policy
Last updated: July 19, 2026
We value the work of security researchers. If you believe you have found a vulnerability in an Ankra service, we want to hear about it, and this policy explains how to tell us and what you can expect in return.
Report vulnerabilities to[email protected].
Scope
This policy covers the services we build and operate:
- ankra.ai - this website
- platform.ankra.app - the Ankra platform
- docs.ankra.ai - our documentation
Out of scope
The following are outside the scope of this policy:
- Denial-of-service testing of any kind, including volumetric and resource-exhaustion attacks
- Social engineering of Ankra staff, contractors, or users, including phishing
- Vulnerabilities in third-party services we use, such as Auth0 - please report those to the vendor directly
- Physical attacks against Ankra offices, infrastructure, or people
How to report
Email [email protected] and include as much of the following as you can:
- A description of the vulnerability and where you found it (URL, endpoint, or component)
- Step-by-step instructions to reproduce it
- Your assessment of the impact - what an attacker could actually do with it
- Any proof-of-concept code, screenshots, or logs that support the report
Please avoid accessing, modifying, or deleting data that is not yours, stop as soon as you have enough evidence to demonstrate the issue, and give us a reasonable window to fix it before any public disclosure.
Our commitment
We will acknowledge your report within 3 business days.
We will keep you informed as we triage, validate, and fix the issue, and we will tell you when it is resolved.
Safe harbor
Security research carried out in good faith and in line with this policy is welcome here. We will not pursue or support legal action against you for it, and we consider such research authorised. If a third party takes action against you for research that complies with this policy, we will make it known that your work was conducted under these terms.
Bug bounty
We do not run a paid bug bounty programme today, and we would rather say that plainly than imply otherwise. Reports still matter to us, we still fix them, and we are grateful for every one.
Contact
Security reports: [email protected]. Anything else: [email protected].