Vulnerability Disclosure

Last updated 2026-08-02

If you have found a security problem in ValiCrew, we want to hear about it.

How to report

Email [email protected] with:

  • what you found and where
  • the steps to reproduce it
  • what an attacker could do with it
  • how you would like to be credited, if at all

Please report in English, and please do not open a public issue or post about it before we have had a chance to fix it.

What we promise

We will acknowledge your report within 3 business days.

We will tell you what we assess the severity to be, keep you updated while we work on a fix, and let you know when it is deployed. If we decide something is not a vulnerability, we will explain why rather than going quiet.

We will credit you if you want to be credited.

Safe harbour

If you follow this policy in good faith, we will not pursue legal action against you, and we will treat your research as authorised for the purposes of our Acceptable Use Policy.

That protection depends on you:

  • only testing against your own workspace or a trial account you created — never against another customer's data
  • stopping as soon as you have confirmed a problem, and not extracting more data than needed to demonstrate it
  • not degrading the service — no denial-of-service, no automated scanning heavy enough to affect other customers
  • not modifying or deleting data that is not yours
  • giving us reasonable time to fix it before disclosing publicly

If you accidentally access data belonging to someone else, stop, tell us, and delete it.

In scope

  • valicrew.com and its customer workspace subdomains
  • the ValiCrew application and its API

Out of scope

  • our third-party providers — report those to them (Stripe, Microsoft, Google, Cloudflare, Oracle all run their own programmes)
  • findings from automated scanners with no demonstrated impact
  • missing hardening headers with no exploitable consequence
  • social engineering of our staff or customers
  • physical attacks
  • vulnerabilities that require an already-compromised device or a rooted browser

Rewards

We do not currently run a paid bug bounty. We will credit you, and we will thank you properly.

Contact

[email protected]

This policy is also published at /.well-known/security.txt.

Lenouar Artificial Intelligence Developing Services LLC · Al Muroor, Abu Dhabi, United Arab Emirates · Commercial registration CN-6272765

All site policies