Report a vulnerability
A bounded disclosure process for systems operated by Semantic Gate.
How to report
Email security@semanticgate.dev. Include the affected URL or service, steps to reproduce, likely impact, and enough evidence for us to validate the issue safely.
We do not currently publish a public encryption key. To arrange encrypted follow-up, ask in the first email and do not send sensitive material until a secure channel has been agreed.
Scope
Testing is authorized only for these Semantic Gate-operated public assets:
- The public website at semanticgate.dev and www.semanticgate.dev
- The redirect endpoints at semanticgate.ai and www.semanticgate.ai
Out of scope
If you are unsure whether an asset is in scope, ask before testing it.
- Any client-owned or client-branded website, domain, account, content, data, or infrastructure, even when Semantic Gate built or hosts it
- Any subdomain not explicitly named above, including MCP endpoints and development, preview, test, internal, or administrative services
- Third-party services and providers, and employee or personal accounts
Safe harbour
If you act in good faith, stay within the scope above, follow this policy, and report promptly, Semantic Gate will not initiate legal action against you solely for that research. This statement does not authorize activity on third-party systems or bind third parties.
What not to do
- Do not exfiltrate, retain, alter, or destroy data. If you unexpectedly access data that is not yours, stop and report it.
- Do not access another user's account or data, and do not attempt to establish persistence.
- Do not perform denial-of-service testing or automated scanning that could degrade service.
- Do not use social engineering, phishing, physical intrusion, or attacks against staff or suppliers.
- Do not disclose vulnerability details publicly before we have had a reasonable opportunity to investigate and remediate them.
Response expectations
We aim to acknowledge a complete report within seven calendar days and provide an initial triage update within fourteen calendar days. These are targets, not guaranteed service levels. Resolution timing depends on severity and complexity; we will share material updates when practicable.
No bounty
We do not currently offer a bug bounty or payment for reports. Do not incur costs with an expectation of reimbursement.