How disclosure works
Report
Email neville@route5ai.com with steps to reproduce, impact, and any PoC. Prefer clear write-ups over noisy scanners.
Acknowledge
We aim to acknowledge within 2 business days. You will get a tracking note — not silence.
Triage
We classify severity, confirm reproducibility, and scope blast radius. Legal hold / customer notify rules apply when required.
Fix & credit
We patch, verify, and may credit you on acknowledgments if you want. No bounty program yet — honesty over theater.
In scope
- route5ai.com and authenticated product surfaces
- Authentication / session handling, authorization gaps, injection, SSRF, RCE
- Sensitive data exposure in APIs or exports
- Desktop Electron shell sandbox escapes (when applicable)
Out of scope
- Social engineering of Route5 staff or customers
- DoS / volumetric floods without prior coordination
- Reports from automated scanners with no validated impact
- Issues in third-party IdPs / Stripe / Clerk themselves (report upstream)
Safe harbor
If you research in good faith, avoid privacy violations and service disruption, and report promptly, we will not pursue legal action for that research. Do not access other customers’ data. If you accidentally do — stop and tell us immediately.