SECURITY PROTOCOL

Vulnerability Disclosure

Last Updated: January 12, 2026

CytherAI values the security community. We appreciate responsible disclosure and commit to working with researchers to verify and address issues promptly.

Security Contact: security@cytherai.com
For encrypted communication, request PGP key via above email.

Scope

This policy applies to:

Out of Scope

Reporting a Vulnerability

Email security@cytherai.com with:

Response Timeline

Severity Levels

Safe Harbor

We consider security research under this policy to be:

Requirements: Follow responsible disclosure, do not access customer data, do not cause service disruption, report findings promptly.

Coordinated Disclosure

We prefer coordinated disclosure. We will:

Typical disclosure window: 90 days after report or fix availability, whichever comes first.

Hall of Thanks

We publicly acknowledge researchers who report valid vulnerabilities (with permission).

No disclosures yet. Be the first.

Non-Security Contact

For non-security inquiries: contact@cytherai.com