Skip to content

Vulnerability disclosure

We take the security of Gamut AI seriously and welcome reports from security researchers and customers acting in good faith. This page explains how to report a vulnerability and what you can expect from us.

Email [email protected] with the subject line “Security report”. Please include:

  • A clear description of the issue and its potential impact.
  • The steps to reproduce it (proof-of-concept requests, affected URLs or parameters).
  • Any relevant logs, screenshots or sample payloads.
  • How you would like to be credited, if you wish to be.

If you need to share sensitive details, say so in your first message and we will arrange a secure channel.

When you report in good faith and within this policy:

  • We will acknowledge your report promptly and keep you updated on our progress.
  • We will investigate and remediate valid issues as quickly as is practical, prioritised by risk.
  • We will not pursue or support legal action against you for good-faith research conducted within the scope and rules below (safe harbour).
  • We are happy to credit reporters who wish to be acknowledged, once an issue is resolved.

In scope

  • The Gamut AI platform at run.gamutassure.com and its application programming interfaces.
  • This documentation site at docs.gamutassure.com.

Out of scope

  • Third-party services Gamut relies on (hosting, content-delivery, email, identity and model providers). Report those to the relevant provider.
  • Denial-of-service, volumetric or load testing.
  • Social engineering, phishing of staff or customers, and physical attacks.
  • Findings from automated scanners without a demonstrated, exploitable impact.
  • Reports that require a compromised device, a man-in-the-middle position, or a non-current browser to exploit.

To keep testing safe for everyone, please:

  • Only test against accounts and tenants you own or have explicit permission to test.
  • Do not access, modify, delete or exfiltrate data that is not yours.
  • Stop as soon as you have demonstrated a vulnerability, and do not pivot further into systems.
  • Avoid privacy violations, service disruption and any destructive actions.
  • Give us a reasonable opportunity to remediate before any public disclosure, and coordinate timing with us.

We run continuous security review and are commissioning independent third-party penetration testing as we scale. Coordinated disclosure from the research community is a valued part of that programme. See Security & trust for our overall posture.