Last updated: April 2026
The security of Customers and their data is a priority for AIKIT RESEARCH, S.A. This Policy sets out the channel and the conditions under which security researchers and good-faith third parties may report vulnerabilities in the services of AIKIT RESEARCH, S.A.
This Policy covers vulnerabilities identified in:
The following are expressly excluded from the scope of this Policy:
Vulnerability reports must be sent by email to:
The report should include, to the extent possible:
It is recommended that no real third-party data be included in reports.
AIKIT RESEARCH, S.A. undertakes to:
AIKIT RESEARCH, S.A. will not pursue legal action against security researchers who act in good faith and comply with the conditions of this Policy, in particular:
The following acts are excluded from the Safe Harbor above and may give rise to such legal action as may be appropriate:
As of the date hereof, AIKIT RESEARCH, S.A. does not operate a monetary rewards program (bug bounty). Contributions will be publicly acknowledged, where appropriate and with the researcher's consent, on the security page of AIKIT RESEARCH, S.A. AIKIT RESEARCH, S.A. may activate a rewards program in the future by means of an update to this Policy.
This Policy may be updated where justified by changes in the services, in the risks, or in industry best practices. The version in force is available on the AiKit Trust Center page.