Skip to content

Report a vulnerability

Vulnerability Disclosure Policy

Last updated: 2026-08-05

We would rather hear about a vulnerability from you than from an incident. This policy sets out what you may test, how to tell us, what protection you have when you follow it, and what we commit to doing in return.

Safe harbor

If you make a good-faith effort to follow this policy while researching a security issue, we will treat your research as authorized. We will work with you to understand and resolve the issue quickly, and we will not bring or support a civil claim against you in connection with it. If a third party brings action against you for research that followed this policy, we will make that authorization clear.

Two honest limits. This authorization is ours to give only for systems we control, listed below; we cannot authorize testing of a customer's systems or data on their behalf. And a private assurance cannot bind a prosecutor: Finnish criminal law on unauthorized access applies regardless of what we say here. Staying inside the scope and the guidelines below is what keeps that from being a live question.

What you may test

In scope:

  • tai.ga and its subdomains.
  • The Taiga platform's own application, API, and infrastructure, using an account issued to you or an account whose owner has asked you to test.
  • The platform's agents, including their tool use, permission boundaries, and resistance to prompt injection, within your own tenant.
  • Our public interfaces: security.txt, the API catalogue, and the agent-facing endpoints.

Out of scope. Some of this is not ours to authorize, and some of it we simply do not want:

  • Any tenant, account, repository, or cloud environment belonging to a customer. We cannot consent on a customer's behalf, and their data is not ours to expose.
  • Applications the factory has built and deployed into a customer's own cloud account. Those belong to the customer.
  • Denial of service, load testing, or anything that degrades service for others.
  • Social engineering, phishing, or physical access attempts against our people, our suppliers, or the Maria01 campus.
  • Third-party services we use but do not control, such as AWS or GitHub. Report those to the provider.
  • Accessing, modifying, or retaining anyone's data beyond the minimum needed to demonstrate the issue.

Rules of engagement

While testing:

  • Use only the access needed to prove the issue exists. Stop as soon as you have. Do not pivot further into the system.
  • If you encounter personal data, customer code, or credentials, stop, do not save a copy, and tell us in the report. Delete anything you already retrieved once we confirm receipt.
  • Report promptly, and give us a reasonable opportunity to fix the issue before you tell anyone else.
  • Send findings you have verified. Unreviewed scanner output is not a report and we will close it.
  • Do not break the law, and do not extract payment as a condition of disclosure.

How to report

Email security@tai.ga. English or Finnish, whichever you prefer. If you want to encrypt, say so and we will arrange it. Our contact details are also published in our security.txt.

A useful report says what the issue is, where you found it, and how to reproduce it step by step, with whatever evidence you have and your view of the impact. Tell us if you plan to publish and when. If you would like credit, tell us the name to use.

What you can expect from us

  • We acknowledge every report within 3 business days.
  • We give you our assessment, including whether we consider it in scope and how severe we think it is, within 10 business days.
  • We keep you updated at least every 14 days until it is closed.
  • We agree disclosure timing with you rather than imposing it. Our default is that you may publish 90 days after your report, or sooner once a fix is released. If we need longer, we will explain why rather than go quiet.
  • We credit researchers who want credit, and we respect it when you would rather stay anonymous.

We do not pay bounties

There is no bug bounty today and we will not pretend otherwise. What we offer is a fast, honest response, public credit if you want it, and a policy we actually follow. If that changes, this page changes with it.

Changes

We may update this policy. The date at the top shows when it last changed. The version in force for your research is the one published when you started.

Contact

Security reports and questions about this policy go to security@tai.ga

Scope and response commitments verified 2026-08-05. The version in force for your research is the one published when you started.