Legal
Responsible Disclosure
Version 1.0 · Last updated 2026-10-04
Our commitment
Security matters because this Service stores encrypted provider tokens and routes your prompts. If you believe you have found a vulnerability, please tell us. We will work with you in good faith.
How to report
Use the form below, or email hello@ajens.org. Please include:
- A clear description of the issue and its impact.
- Steps to reproduce, with proof-of-concept code or requests where possible.
- The affected URL, endpoint or component, and any version information.
- How we can contact you for follow-up.
Scope
In scope: https://darkcoder.ai, the gateway API under /v1, the admin API under /api, authentication and session handling, and the handling of stored provider tokens and gateway keys.
Out of scope:
- Findings that need physical access, a rooted or already-compromised device, or social engineering of staff or users.
- Denial-of-service, volumetric attacks, or automated scanning that degrades the Service.
- Missing best-practice headers or settings without a demonstrable security impact.
- Vulnerabilities in third-party providers or services (report those to the vendor).
- Reports from automated tools with no validated impact.
Safe harbour
If you act in good faith and follow this policy, we will not pursue legal action against you or ask law enforcement to do so for your research, and we will work with you to understand and resolve the issue.
Please do not
- Access, modify, delete or exfiltrate data that is not yours; stop as soon as you have shown the issue exists.
- Disrupt the Service or other users, or run tests that could degrade availability.
- Use social engineering, phishing or physical attacks.
- Share details publicly before we have fixed the issue and agreed a disclosure date.
What to expect
- We acknowledge reports within 3 business days.
- We aim to triage and give you an initial assessment promptly after that, and keep you updated.
- We aim to fix or mitigate confirmed issues within 90 days, sooner for critical ones, and coordinate public disclosure with you.
- We credit reporters who want it. There is currently no monetary bounty.
Policy last updated: 2026-10-04.