Legal Last updated 21 August 2026

Vulnerability Disclosure Policy

We build a security product, so we hold ourselves to the same standard. Here's how to report a vulnerability, and what we promise in return.

security.txt published · RFC 9116 compliantSafe harbor for researchers · Good-faith testing welcome

Introduction

Dedups.ai takes security seriously. If you believe you've found a security vulnerability in our platform, our downloadable software, or our APIs, we want to hear from you. This policy explains how to report it, and what protection we offer you as a good-faith researcher.

A machine-readable version of this contact information is published at /.well-known/security.txt, per RFC 9116.

Scope

This policy covers:

  • dedups.ai and all its subdomains (app.dedups.ai, api.dedups.ai, etc.)
  • The inspector agent and private API scanner binaries we publish for download
  • Our public APIs

How to Report

Email security@dedups.ai with a description of the issue, steps to reproduce it, and its potential impact. Please include:

  • The URL, endpoint, or binary/version affected
  • Steps to reproduce, or a proof-of-concept if you have one
  • What you believe the impact is

Please do not include real customer data in your report - use test accounts and synthetic data wherever possible.

Safe Harbor

If you make a good-faith effort to comply with this policy during your security research, we will consider your research authorized, we will work with you to understand and resolve the issue quickly, and we will not pursue legal action against you for that research.

This safe harbor applies only if you:

  • Avoid privacy violations, service degradation, and destruction of data
  • Only interact with accounts you own or have explicit permission to test
  • Give us a reasonable amount of time to investigate and fix an issue before disclosing it publicly
  • Do not exploit the vulnerability beyond what is needed to demonstrate it

What to Expect

  • Acknowledgement: within 3 business days of your report
  • Initial assessment: within 10 business days, including our assessment of severity
  • Resolution: timeline depends on severity and complexity - we will keep you updated
  • Credit: with your permission, we're happy to credit you once the issue is resolved

We do not currently run a paid bug bounty program, but we're grateful for responsible disclosure and will acknowledge your report.

Out of Scope

The following are not eligible under this policy:

  • Automated vulnerability scanning that generates high traffic without prior notice to security@dedups.ai
  • Social engineering, phishing, or physical attacks against our staff or offices
  • Denial-of-service or resource-exhaustion testing
  • Findings that require a jailbroken/rooted device or physical access to a customer's device
  • Spam, missing security headers with no demonstrated impact, or best-practice suggestions without a working exploit

Contact Us

To report a vulnerability, or ask a question about this policy: