Skip to content

SECURITY

Responsible disclosure policy.

If you\u2019ve found a security vulnerability in Safua, here\u2019s how to report it \u2014 and what we commit to in return.

IN SCOPE

What we want to hear about.

In scope

  • Vulnerabilities in safua.ai (including all subdomains)
  • Vulnerabilities in the Safua product (signup, signin, Mission Control, IDE, Review Engine)
  • Account takeover, privilege escalation, or data exposure issues
  • Payment flow vulnerabilities (when payments go live)
  • Email injection, SPF/DKIM bypass, or phishing risk vectors
  • Third-party dependency vulnerabilities affecting Safua directly

Out of scope

  • Social engineering attacks targeting Safua staff
  • Physical attacks or denial-of-service
  • Vulnerabilities in third-party services (report to them directly)
  • Missing security headers without demonstrated exploit
  • Self-XSS or clickjacking without demonstrated impact

REPORT

Send a detailed writeup.

Email: security@darkolab.com (preferred)
Machine-readable policy: /.well-known/security.txt

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce (with any required payload, screenshots, or video)
  • The impact you believe this has
  • Your name or handle, if you want credit

We acknowledge receipt within 2 business days. We respond with triage within 5 business days. We fix confirmed high-severity issues within 30 days; lower-severity within 90.

OUR COMMITMENT

Safe harbour for good-faith research.

If you act in good faith, we commit to:

  • Not pursuing legal action against you
  • Not reporting you to law enforcement
  • Acknowledging your contribution (with your permission) on a public Hall of Fame
  • Working with you on coordinated disclosure timing

Good faith means: you don’t access data beyond what’s needed to prove the vulnerability, you don’t degrade service for other users, you don’t exfiltrate data you shouldn’t have, and you give us reasonable time to fix before public disclosure.

Your un-fakeable AI engineering identity starts here.

Join the engineers building proof, not just portfolios.