Reporting a vulnerability
Email support@construktr.ai with a description of the issue, the steps to reproduce it, and any proof-of-concept material. Please report privately by email rather than a public issue or social post, so we can investigate and fix a real problem before it is disclosed.
We will acknowledge your report, investigate it, and work with you to verify and fix confirmed vulnerabilities. We do not currently run a paid bug bounty program.
What we ask
- Give us a reasonable amount of time to investigate and fix an issue before any public disclosure.
- Avoid accessing, modifying, or deleting data that is not yours, beyond what is necessary to demonstrate the issue.
- Do not run automated scanning or load testing against production without contacting us first.
- Act in good faith and avoid privacy violations, service disruption, or degraded experience for other users.
Good-faith security research conducted under this policy is authorized, and we will not pursue legal action against a researcher who follows it.
Machine-readable contact
This policy is also published at /.well-known/security.txt in the RFC 9116 format that security tools and researchers look for automatically.
For anything else, including account or billing questions, use our support page.
