Skip to content

Security policy

Last updated 2026-10-09.

Reporting a vulnerability

To report a vulnerability in the site, its API, its MCP server or the tools repository, email security@aisecwatch.com. Include the affected URL or endpoint, the steps to reproduce the problem and its impact.

Please give the maintainer time to fix the issue before you publish details.

Scope

These are in scope:

These are out of scope:

  • Denial of service and load testing
  • Social engineering
  • Third-party services the site uses

Testing

Do not test with other people's data, and do not degrade the service. The public API is rate limited to 60 requests a minute.

Wrong records

A wrong record is not a vulnerability. Use the "Report a correction" form on the record's page. Changes made to records are listed in the corrections log.

security.txt

The contact address is also published at /.well-known/security.txt.