Responsible Disclosure

Security
Vulnerability Reporting

Antralabs welcomes responsible disclosure of security vulnerabilities. If you discover a security issue, we encourage you to report it responsibly so it can be reviewed and addressed appropriately.

Last updated: June 2026

1. Overview

Antralabs values the contributions of security researchers and the broader security community.

Responsible disclosure helps us identify, assess, and remediate potential security issues that may affect our infrastructure, products, services, and digital platforms.

2. Reporting a Vulnerability

If you discover a potential security vulnerability, please report it to Antralabs as soon as possible using the contact information provided below.

Please include sufficient details to help us reproduce, validate, and investigate the issue.

3. Information to Include

  • Description of the vulnerability
  • Affected system, service, or application
  • Steps required to reproduce the issue
  • Proof-of-concept information where appropriate
  • Potential security impact

4. Scope

This disclosure process applies to Antralabs-owned websites, services, infrastructure, applications, APIs, and digital platforms unless otherwise stated.

5. Research Guidelines

  • Act in good faith at all times
  • Avoid disrupting services
  • Avoid accessing information belonging to other users
  • Avoid modifying, deleting, or destroying data
  • Report findings privately before public disclosure

6. Activities Not Permitted

  • Social engineering attacks
  • Physical security testing
  • Denial-of-service attacks
  • Data destruction or alteration
  • Accessing accounts without authorization

7. Safe Harbor

Antralabs will not pursue legal action against researchers who act in good faith, follow this policy, and report vulnerabilities responsibly.

Researchers are expected to avoid actions that may negatively impact users, systems, services, or data.

8. Response Process

Submitted reports are reviewed and prioritized based on severity, impact, and operational risk.

Antralabs will make reasonable efforts to investigate reported vulnerabilities and implement corrective actions where appropriate.

9. Public Disclosure

We request that researchers avoid public disclosure until Antralabs has had a reasonable opportunity to investigate and address the reported issue.

10. Recognition

Antralabs may acknowledge valid vulnerability reports at its discretion where appropriate and permitted by the reporting party.

11. No Bug Bounty Program

Unless explicitly stated otherwise, Antralabs does not currently operate a public bug bounty or financial reward program.

12. Contact

To report a security issue or submit a responsible disclosure report, contact:

security@antralabs.com