Skip to content Skip to footer
Join our LinkedIn Group and be part of the conversation on AI in life sciences Subscribe to our YouTube channel for the latest MadeAi product updates

Responsible Vulnerability Disclosure Policy

Last Updated: July 13, 2026

Our Commitment to Security

At MadeAi, the security and privacy of our customers, partners, employees, and systems are of utmost importance. We value the contributions of the global security research community in helping us identify and responsibly disclose potential security vulnerabilities.

This Responsible Vulnerability Disclosure (RVD) Policy outlines the process for reporting security vulnerabilities affecting MadeAi-owned products, services, websites, and infrastructure. We are committed to investigating all legitimate reports promptly and working with researchers in a transparent and collaborative manner to enhance the security of our systems.

Scope

This policy applies to security vulnerabilities identified in digital assets that are owned, operated, or managed by MadeAi, including:

  • Corporate websites
  • Customer portals
  • Web applications
  • Mobile applications
  • Public APIs
  • Cloud-hosted services
  • Authentication and identity services
  • Public-facing infrastructure
  • Software products developed and maintained by MadeAi

Assets or services owned and operated by third parties are outside the scope of this policy, even if they are integrated with MadeAi services.

Reporting a Vulnerability

At MadeAi, we maintain our own dedicated security team that manages security operations both periodically and on-demand. This team is responsible for remediating identified vulnerabilities in accordance with our internal vulnerability management policy.

However, if any external bug hunters identify a potential security issue, they should report it exclusively to the following email address:

Security Response Team

Email: secops@madeai.com

To help us investigate efficiently, please include as much of the following information as possible:

  • A clear description of the vulnerability
  • The affected application, website, API, or service
  • The affected URL or endpoint
  • Steps required to reproduce the issue
  • Proof-of-Concept (PoC), screenshots, logs, or sample requests/responses
  • Any tools used during testing
  • The potential business or security impact
  • Suggested remediation (if available)
  • Your name and preferred contact information (optional)

Incomplete reports may require additional information before they can be investigated.

Our Response Process

Upon receiving your report, our Security Response Team will:

  • Acknowledge receipt of your report within 3 business days.
  • Review and validate the reported issue.
  • Assess the severity and business impact using industry-standard methodologies.
  • Prioritize remediation based on risk.
  • Keep you informed of the investigation status when appropriate.
  • Notify you once the vulnerability has been remediated or otherwise addressed.

Please note that remediation timelines vary depending on the complexity, severity, and operational impact of the vulnerability.

Responsible Research Guidelines

To ensure the safety of our customers and services, we ask that researchers:

  • Act in good faith at all times.
  • Respect the privacy and confidentiality of our users.
  • Perform only the minimum testing necessary to validate a vulnerability.
  • Avoid actions that could negatively affect the availability or performance of our services.
  • Immediately stop testing after confirming a vulnerability.
  • Avoid accessing, modifying, downloading, or deleting data belonging to other users.
  • Do not exploit vulnerabilities beyond what is necessary to demonstrate their existence.
  • Maintain confidentiality until MadeAi has had a reasonable opportunity to investigate and remediate the issue.
  • Promptly report discovered vulnerabilities through the contact information provided in this policy.
Prohibited Activities

The following activities are not authorized under this policy:

  • Accessing customer data without authorization.
  • Modifying or deleting production data.
  • Uploading malware, ransomware, or malicious code.
  • Conducting Denial-of-Service (DoS) or Distributed Denial-of-Service (DDoS) attacks.
  • Brute-force attacks, password spraying, or credential stuffing.
  • Social engineering, phishing, or impersonation.
  • Physical security testing.
  • Attempting privilege escalation beyond what is necessary to validate a vulnerability.
  • Persistent access to systems after demonstrating a vulnerability.
  • Automated scanning or testing that significantly impacts system availability.
  • Spam or unsolicited communications.
  • Testing third-party services or infrastructure outside MadeAi’s ownership.
Out of Scope

The following are generally considered out of scope unless accompanied by a demonstrated security impact:

  • Missing HTTP security headers without exploitability.
  • Self-XSS.
  • Clickjacking on pages without sensitive functionality.
  • Missing cookie attributes that cannot be exploited.
  • Missing SPF, DKIM, or DMARC records without an associated security impact.
  • Software version disclosure or banner disclosure.
  • Best-practice recommendations without demonstrable risk.
  • Recently disclosed CVEs without evidence that MadeAi systems are affected.
  • Reports generated solely by automated vulnerability scanners without manual validation.
  • User interface or cosmetic issues.
  • Rate-limiting recommendations without a practical attack scenario.
Safe Harbor

MadeAi supports responsible security research conducted in accordance with this policy.

If you:

  • Act in good faith,
  • Avoid causing harm to our customers or services,
  • Respect privacy,
  • Report vulnerabilities promptly, and
  • Comply with this Responsible Vulnerability Disclosure Policy,

Researchers must not publicly disclose or share MadeAi’s name, the existence or details of the reported vulnerability, affected systems or services, research findings, screenshots, data, or any other information that could identify MadeAi or the reported issue without MadeAi’s prior written authorization.

We request that researchers refrain from any public disclosure, publication, presentation, or communication of vulnerability details or related research findings until MadeAi has had a reasonable opportunity to investigate and remediate the reported issue.

Public disclosure may occur only after both of the following conditions have been satisfied:

  • The reported issue has been investigated and, where applicable, remediated by MadeAi; and
  • The researcher has received explicit written confirmation by email from MadeAi’s designated contact confirming that MadeAi agrees to the proposed public disclosure and the specific MadeAi-related information and research findings that may be disclosed.

Silence, acknowledgment of receipt, or completion of the investigation does not constitute authorization for public disclosure. Researchers should obtain written confirmation before publishing or communicating any information externally. Any proposed disclosure should be coordinated with MadeAi in advance and should clearly identify the information the researcher intends to disclose. MadeAi may request that certain confidential, proprietary, security-sensitive, customer-related, or otherwise protected information be withheld from public disclosure.

Coordinated disclosure is intended to protect MadeAi, its customers, and users while providing researchers an appropriate opportunity to receive acknowledgment for their security research after the reported issue has been addressed.

This Safe Harbor applies only to activities conducted within the scope and guidelines described herein.

Coordinated Disclosure

We request that researchers refrain from publicly disclosing vulnerability details until:

  • The reported issue has been investigated and remediated; or
  • MadeAi has confirmed that public disclosure is appropriate.

Coordinated disclosure helps protect our customers while allowing sufficient time for remediation.

Recognition

MadeAi values contributions from the security community.

With your permission, we may acknowledge responsible security researchers who submit valid vulnerability reports after remediation has been completed.

Submission of a vulnerability report does not entitle the reporter to financial compensation unless explicitly covered by a separate Bug Bounty Program.

Privacy

Information submitted as part of a vulnerability report will be used solely for:

  • Investigating the reported vulnerability.
  • Communicating with the reporter.
  • Improving the security of MadeAi products and services.
  • Meeting legal or regulatory obligations where applicable.

All personal information will be handled in accordance with MadeAi’s Privacy Policy.

Response Timeline

While response times may vary depending on the nature and complexity of the report, our general targets are:

Activity

Target

Acknowledge receipt

Within 3 business days

Initial assessment

Within 5 business days

Validation

As soon as reasonably possible

Status updates

Periodically during the investigation

Remediation

Based on severity and business impact

Closure notification

After remediation or mitigation

Legal Notice

This policy does not authorize activities that violate any applicable laws or regulations.

Researchers are expected to comply with all applicable legal requirements and conduct testing only within the scope described in this policy.

Contact

For all security-related concerns, vulnerability reports, or security questions, please contact:

MadeAi Security Response Team

Email: secops@madeai.com

We sincerely appreciate the efforts of security researchers, customers, and the broader security community in helping us strengthen the security of our products and services. Your responsible disclosure contributes to a safer and more secure digital ecosystem for everyone.