Security
How to report security issues in AtRisk, what we ask of researchers, and our coordinated disclosure expectations.
Last updated: September 9, 2026 · Effective: September 9, 2026
Email contact@atrisk.dev with a clear description of the issue, steps to reproduce, affected URLs or components, and any proof-of-concept that demonstrates impact without exploiting customer data.
Prefer encrypted or cleartext email as available; include a contact method for follow-up. Machine-readable contact details are also in /.well-known/security.txt.
If you research and report in good faith consistent with this policy, we will not pursue legal action against you for that research. We ask that you:
Safe harbor does not cover malicious activity, theft of data, or testing that violates applicable law outside the bounds of this coordinated disclosure process.
We aim to acknowledge reports promptly and to remediate or mitigate within 90 days of a complete report, or to agree an alternate timeline with you. We ask researchers to wait at least 90 days (or until we confirm a fix) before public disclosure, unless we mutually agree otherwise or an actively exploited critical issue requires earlier public warning.
Contact: contact@atrisk.dev
Trust Center: atrisk.dev/security