Vulnerability Disclosure Policy
Last updated: September 29, 2026
We want to hear about security problems in Vulcan and in blacksmithai.net before anyone else does. This page says what is in scope, how to tell us, what we promise in return, and the protection you have when you act in good faith.
1. Safe harbour
If you make a good-faith effort to follow this policy, we will not start or support legal action against you for your research, we will work with you to understand and fix the problem quickly, and we will not ask you to sign anything to report. We consider research under this policy to be authorized under the Computer Fraud and Abuse Act and comparable state law, and exempt from the anti-circumvention rules of the DMCA to the extent it stays within this policy.
Good faith means: you stop and tell us as soon as you find a problem, you access only what is needed to prove it, you do not read, change or download data that is not yours, and you give us reasonable time to fix it before you say anything in public. If you are unsure whether something is covered, ask first at the address below.
2. What is in scope
- vulcan.blacksmithai.net, the Vulcan application and its API (the /api paths on that host).
- www.blacksmithai.net, the marketing site, including its contact form.
- Anything that lets one company in Vulcan see or change another company's data. That is the class of bug we most want to hear about.
- Sign-in, session, two-factor and passkey weaknesses; missing authorization checks; injection; exposure of a credential or a secret.
3. What is out of scope
- Denial of service, load testing, or anything that degrades the service for other people.
- Social engineering, phishing, or physical attempts on our people, offices or devices.
- Third-party services we use (AWS, MongoDB Atlas, Stripe, the AI providers and the rest); report those to the vendor.
- Automated scanning that generates large volumes of traffic or requests; a targeted check is fine, a crawler is not.
- Reports that only cite a missing best-practice header, a version banner, a rate limit you had to work hard to hit, or a finding on a page with no security impact.
- Accessing another customer's real data beyond the minimum needed to show the problem exists. Use two accounts of your own instead.
4. How to report
Email security@blacksmithai.net with the subject line "Security report". Include:
- What you found and where (the URL or API path), and what it lets an attacker do.
- Steps to reproduce it, with the accounts you used (never anyone else's).
- Any screenshots or request and response captures, with other customers' data blacked out.
- How you would like to be credited, if at all.
5. What we promise
- We acknowledge your report within 3 business days.
- We tell you whether it is confirmed, and its severity, within 10 business days.
- We fix confirmed critical and high-severity problems as a priority, and tell you when the fix is live. Lower-severity fixes ride the next release.
- We keep you informed if a fix takes longer, and we agree a disclosure date with you rather than asking you to stay silent indefinitely.
- With your permission, we credit you on this page. We do not run a paid bounty program today.
6. Machine-readable version
This policy is referenced from /.well-known/security.txt on both hosts (RFC 9116). The file names the contact address, this page, and the date the file expires; we renew it yearly.