Coordinated disclosure
Found something? Tell us directly.
Email security@vantio.ai with what you found. That address is the one published in our security.txt, it goes to people rather than a ticket queue, and English is the language we can read fastest.
If you are dealing with a live compromise, send it to that address and say so in the subject line. Do not use the public help assistant for an active incident.
What is in scope
Anything we build, ship, or operate ourselves is fair game.
- The vantio.ai website and anything it serves, including the docs, the portal, and the public APIs behind them.
- Vantio Optics, including the published npm and PyPI packages and the install path they use.
- Vantio Gate, including its policy engine, its decision path, and its administrative surfaces.
- Vantio Phantom Engine and Vantio Enterprise as we ship them, including the enrollment, control, and evidence paths on Linux hosts.
- Anything that would let one tenant, process, or agent reach authority it was never granted.
What is out of scope
These either belong to someone else or cause harm on the way to proving a point.
- Deployments a customer runs on their own infrastructure. Those belong to the customer, so report them to that organization and we will help if they ask us to.
- Denial of service, volumetric load testing, or anything that degrades service for other people.
- Physical attacks, social engineering of our team, and attempts to access accounts that are not yours.
- Scanner output with no demonstrated impact, missing hardening headers on their own, and best-practice suggestions that do not lead to a concrete exploit.
- Findings that only work with privileges an operator already legitimately holds on their own machine.
What to put in the report
A report we can reproduce on the first read gets fixed sooner. You do not need a template, just these five things.
- 01What the issue is, in a sentence, before the detail.
- 02Where you found it: the exact URL, package version, host role, or product surface.
- 03Steps that let us reproduce it, including any request, payload, or configuration involved.
- 04What an attacker gets out of it, and what they would need to start with.
- 05Anything you would like credited, and how you want to be named if we publish a fix note.
What happens after you send it
A person reads it and replies from security@vantio.ai. We tell you whether we reproduced the issue, what we think the impact is, and what we intend to do about it. If we disagree with your severity assessment, we will say so and explain why rather than going quiet.
The inbox is monitored, and we would much rather hear about a problem from you than from a customer. We do not publish a fixed response-time target yet, so if a few days go by without a reply, send a follow-up and we will pick it up.
We would like to keep the finding private until there is a fix available, and we will work with you on timing rather than dictate it. When we ship the fix, we are happy to credit you by name or handle if you want that.
We do not run a paid bug bounty program today.
Safe harbour
If you are researching in good faith, stay inside the scope above, avoid data that is not yours, avoid degrading service for anyone else, and report what you find to us promptly, we will treat your work as authorized and will not pursue legal action over it.
Two honest limits on that. We can only speak for Vantio, so this says nothing about the rights of a hosting provider, a customer, or any other third party whose systems you might touch. And if you are unsure whether something is in bounds, email us first and ask. We will answer.
Not a vulnerability?
If you have a security question about how the products work rather than a finding, the security overview covers the authority chain and the deployment model, and the trust page covers data handling and coverage limits.