Skip to content
decosa

Security

Report a vulnerability

Found a security problem in Decosa, its API or its tools? Email security@decosa.ai. Tell us what you found, how to reproduce it, and what someone could do with it. Screenshots or a short script help.

What we promise

  • We reply within 3 business daysA person acknowledges your report and tells you what happens next. We keep you posted until it's fixed.
  • No legal action for good-faith researchIf you act in good faith, stay within this page and report what you find to us first, we won't take legal action against you or ask anyone else to.
  • Credit, if you want itOnce the fix is out, we'll thank you by name, or keep you anonymous. It's your choice.

What we ask

  • Only test against your own account and your own data. Never access, change or delete anyone else's.
  • Don't run denial-of-service tests, spam, or social engineering against our team or users.
  • Give us a reasonable time to fix a problem before you tell anyone else about it.

The same contact is in our security.txt. For privacy requests about your data, write to privacy@decosa.ai; for anything else, talk to us.