Security & Trust

Responsible Disclosure Policy

Effective date: July, 2026

Our Commitment

At Contego AI, security is fundamental to everything we do.

We appreciate the efforts of security researchers, customers, partners, and members of the security community who help us identify and responsibly disclose potential security vulnerabilities.

If you believe you have identified a security vulnerability affecting a Contego AI website, application, cloud service, or other publicly accessible system, we encourage you to report it to us in accordance with this Responsible Disclosure Policy.

Our goal is to investigate reported vulnerabilities promptly, reduce potential risk, and continually improve the security of our products and services.

Scope

This Policy applies to vulnerabilities affecting:

  • Contego AI public websites
  • publicly accessible web applications
  • customer portals
  • APIs operated by Contego AI
  • cloud-hosted services owned or managed by Contego AI
  • other internet-facing systems owned and operated by Contego AI.

The following are generally outside the scope of this Policy unless specifically authorised:

  • physical security testing
  • social engineering attacks
  • phishing campaigns
  • denial-of-service or distributed denial-of-service (DoS/DDoS) testing
  • spam or unsolicited communications
  • attacks against Contego AI employees or customers
  • third-party systems or services not owned or controlled by Contego AI
  • vulnerabilities requiring physical access to proprietary hardware unless specifically requested by Contego AI.

Reporting a Vulnerability

Please report suspected vulnerabilities by emailing:

privacy@contego.ai

Please include, where possible:

  • a clear description of the vulnerability
  • affected URL, application, service, or system
  • steps required to reproduce the issue
  • proof-of-concept information where appropriate
  • the potential security impact
  • screenshots or supporting evidence where available
  • your contact details if you would like us to follow up

Reports should contain sufficient information to enable us to reproduce and investigate the issue efficiently.

Our Commitment to Researchers

When you submit a report in good faith, Contego AI will make reasonable efforts to:

  • acknowledge receipt of your report promptly
  • investigate the reported issue
  • keep you informed of significant progress where appropriate
  • remediate confirmed vulnerabilities according to their assessed risk
  • treat your report confidentially where reasonably possible

While we value responsible disclosure, submission of a report does not guarantee that the reported issue constitutes a security vulnerability or that a specific remediation timeline will apply.

Responsible Research Expectations

We ask that security researchers:

  • act in good faith
  • avoid actions that could disrupt our services or affect other users
  • avoid accessing, modifying, deleting, or disclosing data belonging to others
  • avoid exploiting vulnerabilities beyond what is reasonably necessary to demonstrate their existence
  • stop testing immediately if personal information or confidential data is encountered
  • provide Contego AI with a reasonable opportunity to investigate and remediate the issue before making any public disclosure

Prohibited Activities

Under this Policy, you should not:

  • intentionally disrupt services
  • access information that is not your own
  • modify or destroy data
  • establish persistent access to any system
  • introduce malware
  • attempt privilege escalation beyond demonstrating the reported issue
  • exploit vulnerabilities after they have been confirmed
  • conduct automated scanning that materially impacts the availability or performance of our systems

Public Disclosure

We request that researchers do not publicly disclose details of a vulnerability until:

  • Contego AI has confirmed the issue
  • an appropriate remediation has been implemented
  • we have agreed upon a coordinated disclosure timeline

Responsible, coordinated disclosure helps protect our customers, partners, and users.

Bug Bounties

Contego AI does not currently operate a public bug bounty or vulnerability reward programme.

Submission of a vulnerability report does not create any entitlement to financial compensation.

Should we establish a bug bounty programme in the future, this Policy will be updated accordingly.

Legal Notice

Nothing in this Policy authorises activities that violate applicable laws or regulations.

Contego AI reserves all legal rights regarding activities that fall outside the scope of this Policy or that cause harm to our systems, customers, employees, or business operations.

Contact Us

If you have questions regarding this Policy, please contact:

Contego AI, Inc.

Email: privacy@contego.ai

Website: www.contego.ai