Vulnerability Disclosure Policy

Last updated: July 19, 2026

We value the work of security researchers. If you believe you have found a vulnerability in an Ankra service, we want to hear about it, and this policy explains how to tell us and what you can expect in return.

Report vulnerabilities to[email protected].

Scope

This policy covers the services we build and operate:

  • ankra.ai - this website
  • platform.ankra.app - the Ankra platform
  • docs.ankra.ai - our documentation

Out of scope

The following are outside the scope of this policy:

  • Denial-of-service testing of any kind, including volumetric and resource-exhaustion attacks
  • Social engineering of Ankra staff, contractors, or users, including phishing
  • Vulnerabilities in third-party services we use, such as Auth0 - please report those to the vendor directly
  • Physical attacks against Ankra offices, infrastructure, or people

How to report

Email [email protected] and include as much of the following as you can:

  • A description of the vulnerability and where you found it (URL, endpoint, or component)
  • Step-by-step instructions to reproduce it
  • Your assessment of the impact - what an attacker could actually do with it
  • Any proof-of-concept code, screenshots, or logs that support the report

Please avoid accessing, modifying, or deleting data that is not yours, stop as soon as you have enough evidence to demonstrate the issue, and give us a reasonable window to fix it before any public disclosure.

Our commitment

We will acknowledge your report within 3 business days.

We will keep you informed as we triage, validate, and fix the issue, and we will tell you when it is resolved.

Safe harbor

Security research carried out in good faith and in line with this policy is welcome here. We will not pursue or support legal action against you for it, and we consider such research authorised. If a third party takes action against you for research that complies with this policy, we will make it known that your work was conducted under these terms.

Bug bounty

We do not run a paid bug bounty programme today, and we would rather say that plainly than imply otherwise. Reports still matter to us, we still fix them, and we are grateful for every one.

Contact

Security reports: [email protected]. Anything else: [email protected].