Security
Vulnerability Disclosure Policy
We welcome good-faith security research. This policy explains how to report a suspected vulnerability, what is in scope, and how we will respond.
Report a vulnerability
Email security@ebconsulting.io. Please include a description of the issue, the affected system or URL, steps to reproduce or a proof of concept, and any relevant logs or screenshots. Let us know if you need to share sensitive details securely.
Scope
- In scope: the Stonepath AI production web application and API and the cloud infrastructure we operate.
- Out of scope: third-party services (AWS, MongoDB Atlas, Stytch, Knock, Anthropic — report to those vendors); denial-of-service testing; social engineering or physical attacks; automated scanner output without demonstrated impact; and issues already known and accepted.
Safe harbor
We will not pursue or support legal action against researchers who act in good faith and follow this policy. Good-faith research conducted under this policy is considered authorized. If you are unsure whether an action is permitted, contact us first.
Rules of engagement
- Access only the data necessary to demonstrate the issue; do not exfiltrate, modify, or retain customer data.
- Do not degrade service availability or run scans that could impact production.
- Give us a reasonable period to investigate and remediate before any public disclosure, and coordinate timing with us.
What to expect from us
- We will acknowledge your report within five business days.
- We will provide a remediation status update and expected timeline.
- We will coordinate disclosure timing with you and credit you if you wish.
Rewards
We do not currently operate a paid bug-bounty program. We are grateful for responsible disclosure and will gladly acknowledge your contribution.