Security Policy

Last updated: 25 May 2026

Machine-readable version: /.well-known/security.txt

1. How to Report a Vulnerability

We take security seriously and welcome reports from the research community. To report a vulnerability, email security@hararai.com.

Please include:

  • A clear description of the issue and the URL or endpoint affected
  • Steps to reproduce, ideally with a proof-of-concept request or short video
  • The impact you believe the issue has (data exposure, auth bypass, etc.)
  • Your name or handle, if you'd like to be credited

If the issue is sensitive, you may encrypt your report with the PGP key published at /.well-known/pgp-key.txt.

2. Response Timeline

We commit to the following response targets:

  • Initial response: within 5 business days of receiving your report
  • Triage decision: within 10 business days (accepted, duplicate, out-of-scope, or informational)
  • Status updates: at least every 14 days while the issue remains open
  • Fix & disclosure: Critical and High-severity issues are typically patched within 30 days; Medium within 90 days. We coordinate disclosure timing with the reporter

3. Safe Harbor

HararAI will not pursue civil action or initiate a criminal complaint against security researchers who:

  • Make a good-faith effort to comply with this policy
  • Avoid privacy violations, destruction of data, and disruption to our service or our customers
  • Only interact with accounts they own or have explicit written permission from the account holder to access
  • Report the vulnerability promptly and give us a reasonable window to remediate before any public disclosure
  • Do not exploit a vulnerability beyond what is necessary to demonstrate impact

If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will make it known that your actions were authorized under this policy.

4. Scope

In scope:

  • https://hararai.com: marketing site
  • https://app.hararai.com: product dashboard
  • https://api.hararai.com: HTTP API
  • HararAI mobile clients (when published)
  • Authentication, session, billing, and tenant-isolation logic
  • AI phone agent (Twilio + Gemini Live bridge)
  • Webhook signature verification (Twilio, Stripe, Meta, Resend, Paperclip)

Out of scope:

  • Vulnerabilities in third-party services (Stripe, Twilio, Vercel, Railway, Cloudflare) — report those directly to the vendor
  • Denial-of-service attacks (volumetric or resource-exhaustion)
  • Social engineering of HararAI staff, customers, or vendors
  • Physical attacks against HararAI offices or infrastructure
  • Missing security headers without a demonstrated exploitation chain (e.g. missing HSTS preload, CSP without a working XSS)
  • Reports from automated scanners without manual verification and a working proof-of-concept
  • Best-practice findings already documented as accepted risk (e.g. permissive CORS on a public endpoint with no credentialed actions)
  • Self-XSS, clickjacking on pages with no sensitive actions, tabnabbing on outbound links
  • Issues that require a fully compromised endpoint or a privileged attacker position to exploit

5. Acknowledgments

We publicly credit researchers who report valid security issues at /security/acknowledgments. If you would prefer to remain anonymous, let us know in your report.

6. Bug Bounty

HararAI does not currently operate a paid bug bounty programme. We may offer recognition, swag, or a discretionary thank-you payment for high-impact reports. Final decision on any reward rests with HararAI.

7. Coordinated Disclosure

We follow a 90-day coordinated-disclosure window by default. We are happy to extend this for complex issues, and we ask reporters to delay public disclosure until a fix has shipped to production. If we are unresponsive past the deadlines in Section 2, you are free to disclose responsibly.