← Trust Center

Vulnerability Disclosure Policy

Effective: April 2026 · In compliance with the Cyber Resilience Act (EU) 2024/2847, Article 11

Our Commitment

AIComply is committed to ensuring the security of our platform and the data our customers entrust to us. We welcome and encourage responsible security research and vulnerability disclosure from the security community. This policy outlines how to report vulnerabilities and what you can expect from us.

Scope

This policy applies to vulnerabilities in:

  • The AIComply web application (app.aicomply.eu)
  • AIComply REST APIs (api.aicomply.eu)
  • AIComply public website (www.aicomply.eu)
  • Supporting infrastructure directly operated by AIComply

Out of scope: Third-party services (Stripe, Supabase, Anthropic), social engineering attacks, denial-of-service attacks, and physical security.

How to Report

Email
security@ai-comply.app

When reporting a vulnerability, please include:

  • A clear description of the vulnerability and its potential impact
  • Detailed steps to reproduce the issue
  • Affected component (URL, API endpoint, feature)
  • Your assessment of severity (Critical / High / Medium / Low)
  • Any proof-of-concept code or screenshots

For sensitive reports, you may encrypt your message using our PGP key available at https://aicomply.eu/.well-known/pgp-key.asc

Response Commitments

Acknowledge receipt48 hours
Initial triage and severity assessment5 business days
Patch for Critical severity30 calendar days
Patch for High severity60 calendar days
Patch for Medium/Low severity90 calendar days
Public disclosure (after patch)Coordinated with reporter

Safe Harbor

We will not pursue legal action against security researchers who:

  • Act in good faith and follow this disclosure policy
  • Avoid accessing, modifying, or deleting data belonging to other users
  • Do not exploit the vulnerability beyond what is necessary for demonstration
  • Report the vulnerability promptly and allow reasonable time for remediation
  • Do not publicly disclose the vulnerability before a patch is available

Recognition

We believe in recognising security researchers who help us protect our platform and our customers. With your permission, we will acknowledge your contribution on this page. We currently do not offer a monetary bug bounty programme, but may introduce one in the future.

CRA Compliance

This vulnerability disclosure policy is maintained in compliance with Article 11 of the Cyber Resilience Act (EU) 2024/2847, which requires manufacturers of products with digital elements to establish and maintain a coordinated vulnerability disclosure policy. Actively exploited vulnerabilities will be reported to ENISA within 24 hours as required by Article 14(2)(a).

For general security enquiries, contact security@ai-comply.app ·  For data protection enquiries, contact dpo@aicomply.eu