Responsible disclosure policy
Last updated: July 2026
The security of our systems and of the data entrusted to us is a priority. We welcome good-faith reports that help us fix vulnerabilities.
1. Principle
If you discover a security vulnerability on our surfaces, we ask you to report it to us privately before any public disclosure, so that we can fix it within a reasonable time.
2. Reporting a vulnerability
Send your report to contact@naciri.ai, specifying:
- a description of the vulnerability and its potential impact;
- the steps to reproduce it;
- the surface concerned (URL, page, feature).
contact@naciri.ai — subject "Responsible disclosure".
3. Scope & good faith
This policy covers research conducted in good faith: accessing only the data strictly necessary to demonstrate a vulnerability, not retaining it, and allowing Naciri AI a reasonable time to fix it before any publication.
4. What is prohibited
Excluded from the good-faith framework, in particular:
- denial-of-service (DDoS) attacks or any test that degrades availability;
- social engineering targeting our staff, partners or clients;
- the destruction, alteration or exfiltration of data;
- access to data beyond what is necessary for the demonstration.
5. Our commitment
We commit to acknowledging your report within five working days, to keeping you informed of its handling, and not to pursue legal action against researchers acting in good faith in accordance with this policy.