Skip to main content
semantic.gate

Report a vulnerability

A bounded disclosure process for systems operated by Semantic Gate.

How to report

Email security@semanticgate.dev. Include the affected URL or service, steps to reproduce, likely impact, and enough evidence for us to validate the issue safely.

We do not currently publish a public encryption key. To arrange encrypted follow-up, ask in the first email and do not send sensitive material until a secure channel has been agreed.

Scope

Testing is authorized only for these Semantic Gate-operated public assets:

  • The public website at semanticgate.dev and www.semanticgate.dev
  • The redirect endpoints at semanticgate.ai and www.semanticgate.ai

Out of scope

If you are unsure whether an asset is in scope, ask before testing it.

  • Any client-owned or client-branded website, domain, account, content, data, or infrastructure, even when Semantic Gate built or hosts it
  • Any subdomain not explicitly named above, including MCP endpoints and development, preview, test, internal, or administrative services
  • Third-party services and providers, and employee or personal accounts

Safe harbour

If you act in good faith, stay within the scope above, follow this policy, and report promptly, Semantic Gate will not initiate legal action against you solely for that research. This statement does not authorize activity on third-party systems or bind third parties.

What not to do

  • Do not exfiltrate, retain, alter, or destroy data. If you unexpectedly access data that is not yours, stop and report it.
  • Do not access another user's account or data, and do not attempt to establish persistence.
  • Do not perform denial-of-service testing or automated scanning that could degrade service.
  • Do not use social engineering, phishing, physical intrusion, or attacks against staff or suppliers.
  • Do not disclose vulnerability details publicly before we have had a reasonable opportunity to investigate and remediate them.

Response expectations

We aim to acknowledge a complete report within seven calendar days and provide an initial triage update within fourteen calendar days. These are targets, not guaranteed service levels. Resolution timing depends on severity and complexity; we will share material updates when practicable.

No bounty

We do not currently offer a bug bounty or payment for reports. Do not incur costs with an expectation of reimbursement.

>
home about work contact back help