Security & Responsible Disclosure
The security of HybridClaw and the protection of our users' data are our highest priority. If you discover a security vulnerability, we would be grateful for a report – we take every report seriously and respond quickly.
Report a vulnerability
Write to us directly at: security@hybridai.one
To help us understand the issue quickly, please include:
- A short description of the vulnerability and where it occurs (URL, feature).
- Steps to reproduce (screenshots welcome).
- Your assessment of what an attacker could do with it.
Vulnerabilities in the open-source HybridClaw runtime can also be reported directly via GitHub Security Advisories.
What we promise
- Acknowledgement of receipt within 48 hours.
- An initial substantive assessment within 7 days.
- If you wish, we will credit you by name on this page once the issue is fixed (Hall of Fame).
Our thank-you
For reports that lead to a confirmed security improvement, we say thank you with free credits for the HybridAI platform – and, if you like, a named mention.
Scope
This policy applies to the hybridclaw.io website and the HybridClaw Managed Cloud, including all associated subdomains.
Out of scope are:
- Denial-of-service attacks and automated load testing.
- Social engineering or phishing against users or the team.
- Spam and reports from purely automated scanners without a demonstrable security impact.
- Vulnerabilities in third-party services we merely integrate (e.g. payment providers).
- Accessing other people's content or data beyond what is strictly necessary as proof.
Safe harbor
Anyone acting in good faith within this policy need not fear legal action from us. Please treat any data you encounter as confidential, delete it after providing proof, and only publish the vulnerability after we have been able to fix it.
security.txt
This information is available in machine-readable form at: /.well-known/security.txt