Vulnerability Disclosure Policy
Minikai builds AI agents for the care and support economy and handles sensitive information on behalf of the people we support. We welcome reports from security researchers who help us keep that information safe. This policy explains how to report a vulnerability and what to expect from us.
How to report a vulnerability
Email security@minikai.com with the subject line Security Vulnerability Report. If your report contains sensitive details, ask us for a secure channel and we will arrange one before you share them.
To help us triage quickly, please include:
- A clear description of the issue and its potential impact.
- Steps to reproduce it, including the affected URLs, parameters, or endpoints.
- Any proof-of-concept code, logs, or screenshots.
- How we can contact you for follow-up questions.
What to expect from us
- We acknowledge your report within 2 business days.
- We provide an initial assessment, once triaged and validated, within 10 business days.
- We keep you updated on remediation progress and let you know when the issue is resolved.
- We triage and track every report as a security incident through our incident management process.
Scope
The following are in scope for this policy:
- minikai.com and its subdomains.
- The Minikai web application.
- The Minikai API.
Out of scope
The following are not eligible under this policy:
- Findings from automated scanners without a demonstrated, exploitable impact.
- Denial of service, volumetric, and brute-force attacks.
- Social engineering, phishing, and physical attacks against our people, customers, or facilities.
- Missing security headers or best-practice suggestions with no demonstrated impact.
- Vulnerabilities in third-party services that we do not control.
Guidance for researchers
When investigating an issue under this policy, please:
- Only test against accounts and data that you own or have explicit permission to access.
- Never access, modify, or delete data belonging to other people.
- Avoid any action that could degrade, disrupt, or damage our services.
- Give us a reasonable opportunity to resolve the issue before any public disclosure.
Safe harbour
We consider security research carried out in good faith and in line with this policy to be authorised. If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you, and we will work with you to understand and resolve the issue promptly. If a third party brings legal action against you for activities conducted in accordance with this policy, we will make it known that your actions were authorised.
Rewards
Minikai does not currently operate a paid bug bounty programme. We are grateful for your help and, with your permission, are happy to acknowledge your contribution once an issue has been resolved.