Security
Report a vulnerability to security@aitoolsay.com and you get a human reply within two business days. Research in good faith within the scope below and we will not pursue legal action against you — that is a commitment, not a courtesy.
Key points at a glance
A summary for orientation only — the full policy below is what actually governs.
Safe harbour for researchers
Report in good faith and we will not pursue you — that is a commitment, not a courtesy.
Acknowledged in 48 hours
Every report gets a human reply within two business days.
Encrypted end to end
TLS everywhere, hashed passwords, and prompts that are never persisted.
Out of scope: disruption
No denial of service, no social engineering, no accessing other people's data.
How we protect the service
- Encryption in transit. TLS on every connection, with HTTP requests redirected to HTTPS.
- Password handling. Hashed with a modern adaptive algorithm and never stored, logged or transmitted in readable form. We cannot tell you your password because we do not know it.
- Two-factor authentication is available on accounts and enforced for administrative access.
- Least privilege. Administrative access is role-scoped and logged.
- Patching. Servers and dependencies are updated on a routine schedule, and out of band for anything critical.
- Payment isolation. Card details go directly to the payment processor. There is no card data on our infrastructure to compromise.
- Minimal retention. Prompts are not persisted and logs rotate within 30 days. The strongest protection for data is not holding it.
Reporting a vulnerability
Email security@aitoolsay.com. A machine-readable version of this policy is published at /.well-known/security.txt.
Please include:
- The affected URL or endpoint.
- What the issue is, and what an attacker could achieve with it.
- Steps to reproduce — a proof of concept helps enormously.
- Any output, screenshots or request/response pairs that show it.
- How you would like to be credited, if you would like to be.
What happens next
- Acknowledgement within 2 business days, from a person.
- Triage and severity assessment within 5 business days, with our reasoning.
- A remediation timeline — critical issues are worked immediately, and we tell you if something will take longer than expected rather than going quiet.
- Confirmation when it is fixed, and an invitation to verify.
- Credit where you want it, once the fix is live.
Safe harbour
If you make a good-faith effort to comply with this policy during your research, we will:
- Consider your research authorised under applicable anti-hacking law.
- Not pursue or support legal action against you in relation to it.
- Work with you to understand and resolve the issue quickly.
- Recognise your contribution publicly if you want that.
If a third party brings action against you for research conducted in line with this policy, we will make it clear that your activity was authorised. We would rather hear about a flaw from you than read about it later.
In scope
- aitoolsay.com and its subdomains.
- The public web application, its APIs, and the authentication and payment flows.
Issues we particularly want to hear about: authentication or authorisation bypass, injection, remote code execution, server-side request forgery, exposure of another user's data, insecure direct object references, stored cross-site scripting, and anything touching payment integrity.
Out of scope
Not because they do not matter, but because reporting them costs us both time:
- Denial of service, volumetric testing or anything degrading the service for other people.
- Social engineering of our staff, users or providers, and physical attacks.
- Automated scanner output with no demonstrated impact.
- Missing best-practice headers with no exploitable consequence.
- Reports about third-party services we merely consume — take those to the provider.
- Self-XSS, clickjacking on pages with no state-changing action, or missing rate limits with no security impact.
- Outdated version banners without a working exploit against our deployment.
Rules of engagement
- Use your own accounts and test data. Never access, modify or retain another person's data.
- Stop at proof. Once you have demonstrated a vulnerability, stop — do not pivot, escalate or persist.
- Do not exfiltrate. If you encounter personal data, stop immediately and tell us what you saw so we can assess exposure.
- Do not disrupt. No destruction, no degradation, no interruption of the service for others.
- Give us time. Please allow 90 days before public disclosure, or less by agreement if the fix ships sooner.
Rewards
We do not currently run a paid bug bounty. We offer public credit, a written acknowledgement you can cite, and a genuinely fast, respectful process. We would rather be honest about that up front than imply a payout that is not there.
If you are a user, not a researcher
If you think your account has been compromised, or you have received something suspicious claiming to be from us, write to security@aitoolsay.com straight away. We would much rather look at ten false alarms than miss one real incident.
Breach notification
If a breach affects your personal data, we notify the relevant supervisory authority within 72 hours where the law requires it, and tell affected people directly where there is a high risk to their rights. What we know, what we do not yet know, and what we are doing about it.
Contact
Security reports: security@aitoolsay.com. Everything else: the contact page.
Everything you wanted to ask
Still stuck? Our team answers every message.
Still have a question? We usually reply within one working day.
Will you take legal action if I report a bug?
No. Research in good faith within the scope and rules on this page and we consider it authorised, will not pursue or support legal action, and will confirm your activity was authorised if a third party comes after you.
How fast will you respond?
A human acknowledgement within 2 business days, triage and severity within 5, then a remediation timeline. If something will take longer than expected we tell you rather than going quiet.
Do you pay a bug bounty?
Not currently. We offer public credit, a written acknowledgement you can cite, and a fast respectful process — we would rather say that plainly than imply a payout that is not there.
What is out of scope?
Denial of service, social engineering, physical attacks, raw scanner output with no demonstrated impact, missing headers with no exploitable consequence, and issues in third-party services we merely consume.
How long before I can disclose publicly?
Please allow 90 days, or less by agreement if the fix ships sooner. We will keep you updated rather than leaving you waiting on silence.
I found personal data during testing. What now?
Stop immediately, do not download or retain it, and tell us what you saw so we can assess exposure. Continuing to access it takes you outside safe harbour.
Is there a security.txt?
Yes, at /.well-known/security.txt — the machine-readable version of this policy.
Something here unclear?
Legal writing is easy to get wrong. If any part of this page is ambiguous — or you think it is mistaken — tell us and we will fix the wording.