Vulnerability disclosure
We take the security of Gamut AI seriously and welcome reports from security researchers and customers acting in good faith. This page explains how to report a vulnerability and what you can expect from us.
How to report
Section titled “How to report”Email [email protected] with the subject line “Security report”. Please include:
- A clear description of the issue and its potential impact.
- The steps to reproduce it (proof-of-concept requests, affected URLs or parameters).
- Any relevant logs, screenshots or sample payloads.
- How you would like to be credited, if you wish to be.
If you need to share sensitive details, say so in your first message and we will arrange a secure channel.
Our commitment to you
Section titled “Our commitment to you”When you report in good faith and within this policy:
- We will acknowledge your report promptly and keep you updated on our progress.
- We will investigate and remediate valid issues as quickly as is practical, prioritised by risk.
- We will not pursue or support legal action against you for good-faith research conducted within the scope and rules below (safe harbour).
- We are happy to credit reporters who wish to be acknowledged, once an issue is resolved.
In scope
- The Gamut AI platform at run.gamutassure.com and its application programming interfaces.
- This documentation site at docs.gamutassure.com.
Out of scope
- Third-party services Gamut relies on (hosting, content-delivery, email, identity and model providers). Report those to the relevant provider.
- Denial-of-service, volumetric or load testing.
- Social engineering, phishing of staff or customers, and physical attacks.
- Findings from automated scanners without a demonstrated, exploitable impact.
- Reports that require a compromised device, a man-in-the-middle position, or a non-current browser to exploit.
Rules of engagement
Section titled “Rules of engagement”To keep testing safe for everyone, please:
- Only test against accounts and tenants you own or have explicit permission to test.
- Do not access, modify, delete or exfiltrate data that is not yours.
- Stop as soon as you have demonstrated a vulnerability, and do not pivot further into systems.
- Avoid privacy violations, service disruption and any destructive actions.
- Give us a reasonable opportunity to remediate before any public disclosure, and coordinate timing with us.
A note on our assurance roadmap
Section titled “A note on our assurance roadmap”We run continuous security review and are commissioning independent third-party penetration testing as we scale. Coordinated disclosure from the research community is a valued part of that programme. See Security & trust for our overall posture.
- Security & trust: how Gamut protects your data.
- Support: other ways to reach the team.