Legal
Vulnerability disclosure policy
How to report a security issue in XS1's own website and systems, what is in scope, and what you can expect from us. Good-faith research under this policy is welcome.
- Effective
- Effective October 2026
- Applies to
- Applies to xs1.ai
- Reading time
- 2 min read
Draft — pending legal review. This text describes how the site works today; the wording may change after review.
In short
Report through the contact form with the topic set to Security report.
We acknowledge reports within 1–2 business days and keep you updated until it is fixed.
Good-faith research that follows this policy is authorized — we will not pursue legal action over it.
XS1's research models, including Polaris, are not publicly accessible and are out of scope.
How a report moves
You report
Contact form, topic Security report.
We acknowledge
Within 1–2 business days.
We assess
Reproduce it, gauge the impact, keep you updated.
We fix
Then confirm when it's done.
Coordinated disclosure
Credit, with your permission.
Found something? Keep the first message short — no exploit code or personal data.
Report a security issueOur commitment
XS1 works on AI for high-stakes fields, including security research, and we hold our own systems to the same standard. If you find a vulnerability in our website or systems, we want to hear about it and we will work with you to fix it.
Scope
In scope
- The xs1.ai website, including its pages, forms and public endpoints.
- Subdomains of xs1.ai operated by XS1.
- The operator login and password-reset pages — without guessing or brute-forcing credentials.
Out of scope
- Third-party services we use, such as hosting, email delivery or fonts — please report those to the provider.
- Denial-of-service, load or stress testing.
- Social engineering, phishing or physical attacks on XS1 staff or partners.
- Flooding the contact or request forms.
- Automated scanner output or missing best-practice settings without a demonstrated, exploitable impact.
- XS1's research models and programs, including Polaris. They are not publicly accessible and are not a testing target.
How to report
Use the contact form and choose Security report. Please include:
- What you found and where — the URL or component.
- Steps to reproduce it.
- The impact you believe it has.
- How we can reach you.
Keep the first message short
Leave out exploit code, secrets and any personal data you came across. If we need more detail, we will arrange a secure way to share it.
Our machine-readable contact details are published at /.well-known/security.txt.
What to expect from us
- We acknowledge your report within 1–2 business days.
- We assess it, tell you whether we can reproduce it, and keep you updated while we work on a fix.
- We tell you when it is fixed.
- With your permission, we credit you when we talk about the fix.
XS1 does not currently run a paid bug bounty.
Good-faith research
If you make a good-faith effort to follow this policy, we consider your research authorized, we will not pursue or support legal action against you for it, and we will work with you to understand and fix the issue quickly.
If you are unsure whether something is allowed, ask us first through the contact form.
Rules for testing
- Only test what is in scope.
- Access no more data than you need to show the issue. If you come across personal or confidential data, stop, do not keep or share it, and tell us.
- Do not modify or delete data, or degrade the service for anyone else.
- Do not brute-force credentials or try to use accounts that are not yours.
- Do not use social engineering, phishing or physical attacks.
- Give us reasonable time to fix the issue before disclosing it.
Coordinated disclosure
Please keep the details private until we have released a fix or 90 days have passed since your report, whichever comes first, unless we agree otherwise. If we need more time, we will tell you why.
Received a disclosure from XS1?
XS1 Cyber's research can surface vulnerabilities in other organizations' software. We report them to the affected parties first, under coordinated disclosure. If you have received a report that says it comes from XS1 and want to verify it or respond, reach us through the contact form rather than replying to a message you cannot verify.
Contact
Report a security issue. For anything else, contact XS1.