Security

Vulnerability Disclosure Policy

We welcome good-faith security research. This policy explains how to report a suspected vulnerability, what is in scope, and how we will respond.

Report a vulnerability

Email security@ebconsulting.io. Please include a description of the issue, the affected system or URL, steps to reproduce or a proof of concept, and any relevant logs or screenshots. Let us know if you need to share sensitive details securely.

Scope

  • In scope: the Stonepath AI production web application and API and the cloud infrastructure we operate.
  • Out of scope: third-party services (AWS, MongoDB Atlas, Stytch, Knock, Anthropic — report to those vendors); denial-of-service testing; social engineering or physical attacks; automated scanner output without demonstrated impact; and issues already known and accepted.

Safe harbor

We will not pursue or support legal action against researchers who act in good faith and follow this policy. Good-faith research conducted under this policy is considered authorized. If you are unsure whether an action is permitted, contact us first.

Rules of engagement

  • Access only the data necessary to demonstrate the issue; do not exfiltrate, modify, or retain customer data.
  • Do not degrade service availability or run scans that could impact production.
  • Give us a reasonable period to investigate and remediate before any public disclosure, and coordinate timing with us.

What to expect from us

  • We will acknowledge your report within five business days.
  • We will provide a remediation status update and expected timeline.
  • We will coordinate disclosure timing with you and credit you if you wish.

Rewards

We do not currently operate a paid bug-bounty program. We are grateful for responsible disclosure and will gladly acknowledge your contribution.