security@tenovaai.com

For reporting security vulnerabilities. We acknowledge all reports within 72 hours.

1. Scope

In Scope

Out of Scope

2. How to Report

Send your report to security@tenovaai.com with the following information:

Please do not include sensitive data (credentials, tokens, personal information of other users) in your report beyond what is necessary to demonstrate the vulnerability.

3. What to Expect

Stage Timeline
Acknowledgment of your report Within 72 hours
Initial assessment and triage Within 7 days
Status update (if fix is underway) Within 14 days
Remediation for Critical/High severity Target 30 days
Remediation for Medium/Low severity Target 90 days

We will keep you informed of progress and notify you when the issue has been resolved.

4. Safe Harbor

If you conduct security research in good faith and in accordance with this policy, we consider your research to be authorized. We will not pursue legal action against researchers who:

5. Coordinated Disclosure

We follow coordinated disclosure practices consistent with ISO 29147. We ask that reporters:

We are committed to transparency. Once a vulnerability has been remediated, we will credit the reporter (unless they prefer to remain anonymous) and may publish a summary of the issue and fix.

6. Recognition

We value the work of security researchers. For valid, in-scope reports, we offer:

We do not currently operate a paid bug bounty program.

7. Qualifying Vulnerabilities

Examples of vulnerabilities we are interested in:

Examples of reports that typically do not qualify:

Acknowledgments

No vulnerabilities have been reported through this program yet. Responsible researchers who submit valid reports will be listed here with their permission.