Report a vulnerability

Send to

[email protected]

PGP not currently offered — if that's a blocker for your report, say so and we'll work something out. Machine-readable contact: /.well-known/security.txt (RFC 9116).

Please include: affected URL or repo/commit, a clear reproduction (steps, request/response, or PoC), impact assessment, and your contact info for follow-up. Reports with a working repro get triaged fastest.

Scope

  • ainumbers.co — the tool suite, ChainGraph/OCG chains and kernels, the MCP server at mcp.ainumbers.co
  • Helm — github.com/PostOakLabs/ainumbers-helm (daemon, verifier, UI, kernels)
  • Out of scope: social engineering, physical attacks, denial-of-service testing, third-party services we don't operate (GitHub, Cloudflare, DreamHost themselves)

Safe harbor

Good-faith security research conducted under this policy — without accessing, modifying, or exfiltrating data beyond what's needed to demonstrate the issue, and without service disruption — will not trigger legal action from us. If in doubt about whether a test is in scope, ask first.

Credit

With your permission, we're happy to credit you in release notes or the fix commit once it ships. Confirmed vulnerabilities are published as GitHub Security Advisories on the affected repo.