Vulnerability disclosure
How to report security issues in Seal — VDP, not a paid bounty (yet)
Vulnerability disclosure
CompAI / enterprise trust surface (SEA-71 twin of PILE-204). This is a vulnerability disclosure policy (VDP) — not a managed paid bug bounty.
Report a vulnerability
Do not open a public GitHub issue for security reports.
Email security@vortex.nyc (also listed in
/.well-known/security.txt).
Include: affected route or component, reproduction steps, and impact.
Scope
| In scope | Out of scope |
|---|---|
Hosted seal.nyc / api.seal.nyc and the open-source Seal Worker code |
Your self-host config, secrets, DNS, or Cloudflare account settings |
| Auth, document storage, signing, webhooks, SCIM/SSO | Social engineering, physical attacks, DoS volume tests without coordination |
What we do
- Acknowledge receipt within a few business days.
- Triage and remediate based on severity.
- Credit reporters who want it (optional) after a fix ships.
Paid bounty / HackerOne: not offered yet. When we add one, this page will
say so — until then, responsible disclosure to security@vortex.nyc is the
path.
Related
- Privacy & incidents
- Production checklist
- Repo
SECURITY.md