1. Scope
In Scope
- SWT3 AI Witness Protocol SDKs (Python, TypeScript, Rust, C#, Ruby) published on official registries
- SWT3 MCP Server (
@tenova/swt3-mcp)
- The Axiom Sovereign Engine platform at
sovereign.tenova.io
- Public APIs at
sovereign.tenova.io/api/
- The TeNova landing page at
tenova.io
Out of Scope
- Third-party services (authentication providers, cloud infrastructure, CDN)
- Social engineering, phishing, or physical attacks
- Denial of service (DoS/DDoS) attacks
- Automated scanning that degrades service availability
- Vulnerabilities in dependencies that are already publicly disclosed (report upstream)
- Reports from automated tools without a demonstrated proof of concept
2. How to Report
Send your report to security@tenovaai.com with the following information:
- Description of the vulnerability and its potential impact
- Steps to reproduce, including any tools, scripts, or payloads used
- Affected component (SDK, API endpoint, platform page)
- Your assessment of severity (Critical, High, Medium, Low)
- Your name or handle (for acknowledgment, if desired)
Please do not include sensitive data (credentials, tokens, personal information of other users) in your report beyond what is necessary to demonstrate the vulnerability.
3. What to Expect
| Stage |
Timeline |
| Acknowledgment of your report |
Within 72 hours |
| Initial assessment and triage |
Within 7 days |
| Status update (if fix is underway) |
Within 14 days |
| Remediation for Critical/High severity |
Target 30 days |
| Remediation for Medium/Low severity |
Target 90 days |
We will keep you informed of progress and notify you when the issue has been resolved.
4. Safe Harbor
If you conduct security research in good faith and in accordance with this policy, we consider your research to be authorized. We will not pursue legal action against researchers who:
- Make a good-faith effort to avoid privacy violations, data destruction, and disruption of service
- Only interact with accounts you own or with explicit permission of the account holder
- Do not exploit a vulnerability beyond what is necessary to confirm its existence
- Report the vulnerability promptly and do not disclose it publicly before we have had a reasonable opportunity to address it
- Do not use the vulnerability for financial gain beyond any recognition we may offer
5. Coordinated Disclosure
We follow coordinated disclosure practices consistent with ISO 29147. We ask that reporters:
- Allow us reasonable time to investigate and remediate before any public disclosure
- Coordinate the timing of any public disclosure with us
- Do not disclose to third parties before the issue is resolved, unless we are unresponsive beyond the timelines above
We are committed to transparency. Once a vulnerability has been remediated, we will credit the reporter (unless they prefer to remain anonymous) and may publish a summary of the issue and fix.
6. Recognition
We value the work of security researchers. For valid, in-scope reports, we offer:
- Public acknowledgment on this page (with your permission)
- A letter of appreciation for your professional records
We do not currently operate a paid bug bounty program.
7. Qualifying Vulnerabilities
Examples of vulnerabilities we are interested in:
- Authentication or authorization bypasses
- Injection vulnerabilities (SQL, command, template, header)
- Cross-site scripting (XSS) or cross-site request forgery (CSRF)
- Sensitive data exposure in API responses
- Cryptographic weaknesses in the SWT3 fingerprint formula or signing implementation
- Anchor forgery or witness record tampering
- Privilege escalation between tenant boundaries
- Server-side request forgery (SSRF)
Examples of reports that typically do not qualify:
- Missing HTTP headers that do not lead to a demonstrated exploit
- TLS configuration preferences (we enforce TLS 1.3)
- Content injection in error pages without demonstrated impact
- Rate limiting observations without a demonstrated abuse scenario
- Reports from automated scanners without manual verification
Acknowledgments
No vulnerabilities have been reported through this program yet. Responsible researchers who submit valid reports will be listed here with their permission.