Security Policy
Last updated: 25 May 2026
Machine-readable version: /.well-known/security.txt
1. How to Report a Vulnerability
We take security seriously and welcome reports from the research community. To report a vulnerability, email security@hararai.com.
Please include:
- A clear description of the issue and the URL or endpoint affected
- Steps to reproduce, ideally with a proof-of-concept request or short video
- The impact you believe the issue has (data exposure, auth bypass, etc.)
- Your name or handle, if you'd like to be credited
If the issue is sensitive, you may encrypt your report with the PGP key published at /.well-known/pgp-key.txt.
2. Response Timeline
We commit to the following response targets:
- Initial response: within 5 business days of receiving your report
- Triage decision: within 10 business days (accepted, duplicate, out-of-scope, or informational)
- Status updates: at least every 14 days while the issue remains open
- Fix & disclosure: Critical and High-severity issues are typically patched within 30 days; Medium within 90 days. We coordinate disclosure timing with the reporter
3. Safe Harbor
HararAI will not pursue civil action or initiate a criminal complaint against security researchers who:
- Make a good-faith effort to comply with this policy
- Avoid privacy violations, destruction of data, and disruption to our service or our customers
- Only interact with accounts they own or have explicit written permission from the account holder to access
- Report the vulnerability promptly and give us a reasonable window to remediate before any public disclosure
- Do not exploit a vulnerability beyond what is necessary to demonstrate impact
If legal action is initiated by a third party against you for activities conducted in compliance with this policy, we will make it known that your actions were authorized under this policy.
4. Scope
In scope:
https://hararai.com: marketing sitehttps://app.hararai.com: product dashboardhttps://api.hararai.com: HTTP API- HararAI mobile clients (when published)
- Authentication, session, billing, and tenant-isolation logic
- AI phone agent (Twilio + Gemini Live bridge)
- Webhook signature verification (Twilio, Stripe, Meta, Resend, Paperclip)
Out of scope:
- Vulnerabilities in third-party services (Stripe, Twilio, Vercel, Railway, Cloudflare) — report those directly to the vendor
- Denial-of-service attacks (volumetric or resource-exhaustion)
- Social engineering of HararAI staff, customers, or vendors
- Physical attacks against HararAI offices or infrastructure
- Missing security headers without a demonstrated exploitation chain (e.g. missing HSTS preload, CSP without a working XSS)
- Reports from automated scanners without manual verification and a working proof-of-concept
- Best-practice findings already documented as accepted risk (e.g. permissive CORS on a public endpoint with no credentialed actions)
- Self-XSS, clickjacking on pages with no sensitive actions, tabnabbing on outbound links
- Issues that require a fully compromised endpoint or a privileged attacker position to exploit
5. Acknowledgments
We publicly credit researchers who report valid security issues at /security/acknowledgments. If you would prefer to remain anonymous, let us know in your report.
6. Bug Bounty
HararAI does not currently operate a paid bug bounty programme. We may offer recognition, swag, or a discretionary thank-you payment for high-impact reports. Final decision on any reward rests with HararAI.
7. Coordinated Disclosure
We follow a 90-day coordinated-disclosure window by default. We are happy to extend this for complex issues, and we ask reporters to delay public disclosure until a fix has shipped to production. If we are unresponsive past the deadlines in Section 2, you are free to disclose responsibly.