Skip to content
Plan a training run
Legal

Vulnerability Disclosure Policy

Last updated: December 31, 2025Effective: December 31, 2025Version: 1

1. Introduction

At SF Tensor, we take security seriously and welcome responsible reports from security researchers and the public. If you discover a potential vulnerability, privacy issue, or exposed data related to our systems, please notify us at security@sf-tensor.com.

2. Scope

This policy covers all digital assets owned, operated, or maintained by SF Tensor, including:

  • Websites
  • APIs
  • Backend and cloud infrastructure

3. Out of Scope

The following are not covered under this policy:

  • Third-party services or platforms not controlled by SF Tensor
  • Social media accounts
  • Physical security issues

If you discover a vulnerability in out-of-scope systems, please report it to the appropriate vendor or authority.

4. Our Commitments

  • We will acknowledge your report and begin validating the issue within 3 business days.
  • We will keep you informed and address confirmed vulnerabilities promptly.
  • We provide Safe Harbor for good-faith research conducted under this policy.

5. Your Responsibilities

  • Act in good faith, follow this policy, and report issues promptly using our official channel.
  • Perform testing in a controlled manner using standard security tools; automated, mass, AI-driven, or high-volume methods are not permitted.
  • Test only in-scope systems, limit data access to what's necessary, and stop immediately if you encounter sensitive data.
  • Avoid actions that compromise data, disrupt services, or harm users.
  • Allow 60 days before public disclosure unless otherwise agreed.
  • Do not engage in coercion or extortion.

6. How to Report

Send vulnerability reports to security@sf-tensor.com with:

  • A clear description of the issue
  • Steps to reproduce
  • Any supporting evidence (screenshots, logs, etc.)

7. Safe Harbor

If you follow this policy:

  • We will not take legal action against you for your research
  • If a third party initiates action, we will clarify that your testing was allowed under our policy

If you're unsure whether your activity is permitted, please contact us (security@sf-tensor.com) before proceeding.

8. Rewards

SF Tensor may offer monetary rewards for significant, well-documented vulnerabilities. Rewards are discretionary and based on the issue's impact and the clarity of the report.