Vulnerability disclosure policy
We welcome good-faith security research. If you believe you have found a vulnerability in entum.ai or the ENTUM platform, we want to hear about it.
How to report
- Email security@entum.ai with a description of the issue, steps to reproduce, and the affected URL or component.
- We acknowledge reports within 3 business days and keep you informed as we triage and fix.
Ground rules
- Do not access, modify or delete data that is not yours; use test accounts where possible.
- No denial-of-service, spam, social engineering or physical attacks.
- Give us reasonable time to fix the issue before public disclosure.
Safe harbor
- We will not pursue legal action against researchers who follow this policy in good faith.
Draft — pending final owner text; contact security@entum.ai with questions.