← Trust Center

Vulnerability disclosure

We welcome reports from independent researchers. This page covers our scope, the SLA we promise, and how to send us encrypted reports.

How to report

  1. Email [email protected] with a minimal proof-of-concept and the affected URL or endpoint.
  2. For PII-bearing reports, please encrypt with our PGP key (below).
  3. We acknowledge within 1 business day and assign a triage owner within 3.

In scope

  • crawlmind.ai and *.crawlmind.ai (excluding marketing pages)
  • api.crawlmind.ai: all routes
  • Public report viewer at /r/<share-id>

Out of scope

  • Marketing site copy & SEO content
  • Third-party services we use (report to the vendor directly)
  • Rate-limit bypass without demonstrated impact
  • Issues requiring physical access to a customer device

Severity SLA (Q3.6)

SeverityAcknowledgementRemediation
Critical1 business day7 days
High2 business days30 days
Medium3 business days90 days
Low / Info5 business days180 days

PGP key

Fingerprint: TBD: generated by ops on rollout

Public key download: security.asc (404 until the key is generated; see TODO below).

Safe harbour

We will not pursue legal action against researchers who follow this policy in good faith, avoid privacy violations, and give us a reasonable chance to fix issues before public disclosure.