Vulnerability Disclosure Programme

Vulnerability Disclosure Programme

How to report a security issue in Vaquill AI, what we will do about it, and the good-faith protections we extend to researchers who help us protect attorney-client data.

Vaquill AI handles attorney-client-privileged communications, work product, and matter files for lawyers and legal teams. Security is a first-class concern. If you believe you have found a vulnerability in any Vaquill AI product or system, we want to hear from you and we will work with you in good faith to fix it.

This page is aligned with ISO/IEC 29147 (Vulnerability Disclosure) and ISO/IEC 30111 (Vulnerability Handling Processes).

How to report

Send a detailed report to the address below. Please do not file public issues, post on social media, or contact customer support for security matters.

Contact

Email: security@vaquill.ai

For sensitive reports, request our PGP key in your first message and we will send it before you share details.

Please include

  • A clear description of the issue and its impact.
  • Step-by-step reproduction instructions, including URLs, payloads, and screenshots.
  • The Vaquill AI product or surface affected (web app, API, Slack app, etc.).
  • Your suggested CVSS v3.1 severity, if known.
  • Whether you have shared, or plan to share, this information with anyone else.

Scope

The systems below are in scope for this programme. Anything not listed should be reported privately so we can route it correctly, but it may not qualify for coordinated disclosure under this programme.

In scope

  • vaquill.ai and all subdomains (*.vaquill.ai)
  • Vaquill AI web application (app.vaquill.ai)
  • Vaquill AI REST API (api.vaquill.ai)
  • Vaquill AI Slack app (vaquill on Slack)
  • Vaquill AI MCP servers (mcp.vaquill.ai)

Out of scope

  • Denial-of-service (DoS / DDoS) attacks, traffic flooding, or resource exhaustion
  • Social engineering of Vaquill AI staff, customers, or sub-processors
  • Physical attacks on Vaquill AI or sub-processor infrastructure
  • Findings from automated scanners without a working proof of concept
  • Missing security headers (HSTS, X-Frame-Options) without a demonstrable exploit
  • Email spoofing, SPF / DKIM / DMARC misconfigurations on non-customer-facing domains
  • Self-XSS or attacks requiring physical access to a victim device
  • Issues in third-party services we use (please report directly to that vendor)
  • Vulnerabilities in unsupported browsers (older than two major versions behind current)

Rules of engagement

These rules protect Vaquill AI customers and protect you. Please follow them.

  • Test only against accounts you own or accounts you have explicit written permission from the account holder to test.
  • Do not access, modify, exfiltrate, or destroy data that does not belong to you. If you accidentally access another customer's data, stop immediately and report it.
  • Do not run automated scanners against production systems at high request rates. If you need to test something that requires volume, contact us first.
  • Do not attempt to phish, social-engineer, or otherwise manipulate Vaquill AI staff, customers, or sub-processors.
  • Do not perform any activity that would degrade service for other customers.
  • Give us a reasonable opportunity to fix the issue before disclosing it publicly. We follow a 90-day coordinated-disclosure timeline.

What to expect from us

Our response SLAs once we receive a report.

1. Acknowledgment, within 72 hours

We confirm receipt of your report and assign a tracking reference. If we need clarification we will reach out at this stage.

2. Triage and validation, within 5 business days

We reproduce the issue, classify severity (CVSS v3.1), and share our assessment with you. We will tell you whether the issue is in scope and whether we plan to fix it.

3. Remediation, severity-dependent

Critical issues are patched within 7 days. High severity within 30 days. Medium and low severity within 90 days. We will share progress updates with you on request.

4. Coordinated public disclosure, after the fix ships

We follow a 90-day coordinated-disclosure timeline. After the fix is deployed, you are welcome to publish your findings. We will credit you by name in our security advisory if you wish.

Safe harbor

Good-faith research is welcomed

Vaquill AI considers security research conducted under this programme to be authorized activity. If you make a good-faith effort to comply with this policy during your research, we will:

  • Not pursue or support any legal action against you.
  • Work with you to understand and resolve the issue quickly and credit you in our advisory if you wish.
  • Treat your report as confidential and not share your identity with third parties without your permission.

If a third party initiates legal action against you for activity conducted under this programme, we will make it known that your actions were authorized by us.

This policy does not authorize you to break any law or breach any agreement you have with a third party (for example, your employer or your internet service provider). You are responsible for ensuring your testing is lawful where you are located.

Bug bounty

Vaquill AI does not currently operate a paid bug bounty programme. We deeply appreciate every report, and we credit researchers in our security advisories with their consent. We may offer Vaquill AI credit or swag at our discretion for particularly impactful findings.

Related: Security . Privacy Policy . Data Processing Addendum.