AI Understanding is a U.S. 501(c)(3) nonprofit education and research organization. We welcome good-faith security research that helps us protect learners, readers, contributors, and our public-interest publishing infrastructure.
Report a vulnerability
Email [email protected] with the subject Security report. Include the affected URL or component, the potential impact, clear reproduction steps, and the minimum evidence necessary to validate the finding. Please avoid sending personal data, credentials, access tokens, or destructive proof-of-concept material.
Our machine-readable contact is available at /.well-known/security.txt.
Authorized scope
- Public AI Understanding web properties hosted under aiunderstanding.org.
- AI Understanding accounts, test data, and systems you own or have explicit written permission to test.
- Open-source dependencies when testing is performed locally and any third-party finding follows that project's disclosure policy.
- Defensive prompt-injection, data-integrity, authentication, authorization, and application-security testing in controlled environments.
Not authorized
- Testing third-party providers, users, accounts, infrastructure, or data without their written authorization.
- Denial of service, load testing, spam, social engineering, phishing, malware, persistence, or destructive testing.
- Accessing, changing, retaining, or exfiltrating another person's data.
- Testing that degrades service, bypasses payment, violates privacy, or creates avoidable risk for users.
- Public disclosure before AI Understanding and any affected vendor have had a reasonable opportunity to investigate and remediate.
Good-faith safe harbor
When research follows this policy, stays within authorized scope, minimizes harm, and is reported promptly, AI Understanding will treat it as authorized good-faith activity and will not initiate legal action based solely on that research. This safe harbor cannot authorize activity on systems or data owned by someone else.
Our response process
We aim to acknowledge complete reports within five business days, perform an initial triage within ten business days, and provide material status updates during remediation. Timelines vary with severity, reproducibility, vendor coordination, and the risk of premature disclosure. We support coordinated disclosure and will credit researchers who request attribution when doing so is safe and appropriate.
Security research program
Our defensive research focuses on software supply-chain risk, web application security, prompt-injection resilience, source and data integrity, and safe remediation. Read the current scope and baseline at the AI Security & Integrity Lab.
Bug-bounty status
AI Understanding does not currently offer monetary rewards. Please do not incur costs or perform additional testing on the assumption that a bounty will be paid.
Last reviewed: September 1, 2026.