Responsible Vulnerability Disclosure Policy

Last updated: April 2026

Introduction

The security of Customers and their data is a priority for AIKIT RESEARCH, S.A. This Policy sets out the channel and the conditions under which security researchers and good-faith third parties may report vulnerabilities in the services of AIKIT RESEARCH, S.A.

1. Scope

1.1. Systems in scope

This Policy covers vulnerabilities identified in:

  • The AIKIT RESEARCH, S.A. platform accessible at its official production domains.
  • The public APIs and the service endpoints exposed by the platform.

1.2. Systems out of scope

The following are expressly excluded from the scope of this Policy:

  • The institutional marketing website and the public documentation environments.
  • Mobile applications not offered directly by AIKIT RESEARCH, S.A.
  • Third-party services or products (language models, cloud providers, support services) accessible through the platform. Vulnerabilities in such products must be reported to the relevant provider.
  • Vulnerabilities involving social engineering, physical attacks, denial of service (DoS/DDoS), spam, or abuses associated with mailing lists.

2. Reporting channel

Vulnerability reports must be sent by email to:

  • Address: admin@aikit.io
  • Subject:“Vulnerability Disclosure - [brief description]”

The report should include, to the extent possible:

  • The type of vulnerability and the estimated severity.
  • Detailed steps to reproduce it.
  • The URLs, parameters, and requests affected.
  • The potential impact.
  • Any proof of concept (PoC) deemed necessary.

It is recommended that no real third-party data be included in reports.

3. AiKit's commitments

AIKIT RESEARCH, S.A. undertakes to:

  • Acknowledge receipt of the report within three (3) business days of its receipt.
  • Keep the researcher informed of the status of the handling of the vulnerability at a minimum cadence of ten (10) business days until its resolution or closure.
  • Publicly acknowledge the researcher's contribution where the researcher so wishes and the nature of the case so permits.
  • Treat all good-faith reports with confidentiality and diligence.

4. Safe harbor

AIKIT RESEARCH, S.A. will not pursue legal action against security researchers who act in good faith and comply with the conditions of this Policy, in particular:

  • Limiting testing to what is strictly necessary to demonstrate the vulnerability.
  • Not accessing, modifying, exfiltrating, or destroying Customer or third-party data beyond what is indispensable.
  • Not disrupting or degrading the service for other users.
  • Not publicly disclosing the vulnerability before its resolution and without a prior coordination agreement with AIKIT RESEARCH, S.A.
  • Complying with applicable law.

5. Prohibited conduct

The following acts are excluded from the Safe Harbor above and may give rise to such legal action as may be appropriate:

  • Unauthorized access to personal data of Customers or third parties beyond what is strictly necessary to demonstrate the vulnerability.
  • Alteration, destruction, or exfiltration of data.
  • Denial-of-service attacks.
  • Social engineering against the personnel of AIKIT RESEARCH, S.A. or its Customers.
  • Any unlawful activity or any activity contrary to this Policy.

6. Rewards

As of the date hereof, AIKIT RESEARCH, S.A. does not operate a monetary rewards program (bug bounty). Contributions will be publicly acknowledged, where appropriate and with the researcher's consent, on the security page of AIKIT RESEARCH, S.A. AIKIT RESEARCH, S.A. may activate a rewards program in the future by means of an update to this Policy.

7. Updates

This Policy may be updated where justified by changes in the services, in the risks, or in industry best practices. The version in force is available on the AiKit Trust Center page.

Contact