Security policy
Last updated 2026-10-09.
Reporting a vulnerability
To report a vulnerability in the site, its API, its MCP server or the tools repository, email security@aisecwatch.com. Include the affected URL or endpoint, the steps to reproduce the problem and its impact.
Please give the maintainer time to fix the issue before you publish details.
Scope
These are in scope:
- aisecwatch.com
- The API and the MCP server
- The public tools repository at github.com/jackluucoding/aisecwatch-tools
These are out of scope:
- Denial of service and load testing
- Social engineering
- Third-party services the site uses
Testing
Do not test with other people's data, and do not degrade the service. The public API is rate limited to 60 requests a minute.
Wrong records
A wrong record is not a vulnerability. Use the "Report a correction" form on the record's page. Changes made to records are listed in the corrections log.
security.txt
The contact address is also published at /.well-known/security.txt.