Legal

Vulnerability disclosure policy

How to report a security issue in XS1's own website and systems, what is in scope, and what you can expect from us. Good-faith research under this policy is welcome.

Effective
Effective October 2026
Applies to
Applies to xs1.ai
Reading time
2 min read

Draft — pending legal review. This text describes how the site works today; the wording may change after review.

In short

  1. Report through the contact form with the topic set to Security report.

  2. We acknowledge reports within 1–2 business days and keep you updated until it is fixed.

  3. Good-faith research that follows this policy is authorized — we will not pursue legal action over it.

  4. XS1's research models, including Polaris, are not publicly accessible and are out of scope.

How a report moves

  1. You report

    Contact form, topic Security report.

  2. We acknowledge

    Within 1–2 business days.

  3. We assess

    Reproduce it, gauge the impact, keep you updated.

  4. We fix

    Then confirm when it's done.

  5. Coordinated disclosure

    Credit, with your permission.

Found something? Keep the first message short — no exploit code or personal data.

Report a security issue