logo-mark

Cookie Settings

We use cookies to operate this website, improve usability, personalize your experience and improve our marketing. Your privacy is important to us. Privacy Policy.

Security Disclosure Info

Security Disclosure Info

Vulnerability Disclosure Policy

Phaidra, Inc.

v0.1 — June 25, 2026.

The security of our systems and the data entrusted to us is one of Phaidra’s highest priorities. We value the work of security researchers acting in good faith to identify and report potential vulnerabilities, and we welcome your help in keeping our systems safe.

Purpose

Phaidra builds AI software for mission-critical infrastructure. We have established this Vulnerability Disclosure Policy (this “Policy”) to work with security researchers who help us identify potential vulnerabilities in the systems we control.

We also encourage researchers to work with other organizations in our industry. If you discover a vulnerability that affects multiple services, please submit separate reports to each affected organization so that every impacted party can assess and address it.

Scope

In scope. This Policy applies to the following internet-facing systems that Phaidra owns and controls (collectively, “Information Systems”):

  • the phaidra.ai website and related Phaidra-controlled subdomains (including trust.phaidra.ai);

  • the Phaidra Prism web application and customer portal;

  • Phaidra’s public, internet-facing application programming interfaces (APIs); and

  • Phaidra’s internet-facing authentication services.

Out of scope. Only the systems listed above are in scope. Any system, network, device, application, or environment that is not listed is out of scope and must not be tested. This includes, without limitation, any customer system or environment, any third-party or sub-processor system (even where reached through a Phaidra domain or used to deliver our services), and any internal Phaidra system that is not internet-facing. Please follow the relevant third party’s own disclosure process for systems they control.

Do no harm. Do not conduct any testing that could disrupt, degrade, or otherwise affect any system or any customer environment. If you believe you have found an issue that affects an out-of-scope system, do not attempt to validate or exploit it — report your concern to us using the details below and we will coordinate an appropriate, safe response.

Vulnerabilities in Scope

This Policy covers technical vulnerabilities affecting the in-scope Information Systems, such as misconfigurations, cross-site request forgery (CSRF), privilege escalation, SQL injection, cross-site scripting (XSS), server-side request forgery (SSRF), authentication or authorization flaws, and unintended exposure of sensitive data.

The following are excluded, subject to Phaidra’s discretion:

  • general security, email, or SSL/TLS best-practice findings without a working proof-of-concept;

  • physical intrusion, or compromises that rely on an insider;

  • rate-limiting or brute-force issues on non-authenticated endpoints;

  • social engineering (including phishing, vishing, or smishing);

  • account takeovers, including brute-force attacks on accounts that are not your own;

  • denial-of-service (DoS) testing, or testing that generates substantial traffic;

  • clickjacking on pages with no sensitive actions;

  • missing HttpOnly or Secure flags on cookies;

  • any widely publicized zero-day vulnerability with no patch, or with a patch available for fewer than 30 days; and

  • issues that exist solely within an out-of-scope or third-party system.

AI Model Behavior and “Jailbreaks”

Reports about AI model behavior — such as harmful or unexpected model outputs, or “jailbreaks” — are welcome but are handled separately from technical security vulnerabilities. Please send those to VDP@phaidra.ai with “AI SAFETY” in the subject line. Technical vulnerabilities in AI-enabled features that lead to unauthorized access or exposure of data are in scope and should be reported through this Policy in the usual way.

How to Submit a Report

Please report security vulnerabilities promptly by email to VDP@phaidra.ai. For sensitive reports, we encourage you to encrypt your submission with our PGP key, published at phaidra.ai/products/security-disclosure-info (bottom of page) (key fingerprint: 620FBC12C66E48C9C8E3F5DCCCA485C34F1FA850). Please include one vulnerability per report, with:

  • a summary, and the type and severity of the vulnerability;

  • the steps required to reproduce it, and the URL or location affected;

  • supporting proof-of-concept material (scripts, screenshots, or recordings);

  • the potential impact, if applicable; and any plans for public disclosure.

Good-Faith Research Guidelines

Phaidra retains sole discretion to determine whether you have acted in good faith and in accordance with this Policy. We will generally presume good faith if you abide by this Policy and agree that:

  • you test only to identify and report a potential vulnerability;

  • you do not attempt to access, test, or disrupt any system, network, or environment that is not expressly listed as in scope, including any customer or third-party environment, and you take no action that could affect a live or customer environment;

  • you exploit a vulnerability only to the minimum extent needed to confirm it exists, and you do not access, acquire, or use data reachable through it;

  • you do not access the content of any communications or data unless access is inadvertent, and you do not exfiltrate, download, or retain any data — reporting any inadvertent access to us;

  • you coordinate the timing of any public disclosure with us. We fully support your right to disclose vulnerabilities and to report similar issues to other vendors, and will never attempt to restrict such disclosures;

  • you do not compromise an account that is not your own, and do not perform social-engineering attacks against Phaidra personnel;

  • you do not require payment or compensation as a condition of disclosure, and do not make threats;

  • you are not on any applicable sanctions list (including the U.S. OFAC SDN list) and do not reside in a sanctioned country; and

  • you comply with all applicable laws.

If you are unsure whether your planned research is consistent with these guidelines, contact us at VDP@phaidra.ai before proceeding.

What You Can Expect From Us

We take all good-faith reports seriously. If we determine (in our sole discretion) that a vulnerability exists, we will validate it, confirm it with you, and take steps we determine to be appropriate to address it. We will also:

  • protect your name and contact information, and not disclose it without your consent unless required by law;

  • refrain from legal action as described in the Safe Harbor section below;

  • with your permission, credit your contribution in any public disclosure we choose to make; and

  • aim to acknowledge your submission within five (5) business days and make best efforts to keep you updated.

Recognition and rewards. This is not a paid bug-bounty program. However, Phaidra reserves the right, in its sole discretion, to recognize exceptional reports — including through public acknowledgment or, on a case-by-case basis, a discretionary reward. Any reward is entirely discretionary, is not an entitlement, and is subject to applicable law.

Safe Harbor

If, in our sole determination, you make a good-faith effort to research and disclose vulnerabilities in accordance with this Policy, we will consider your activity authorized and will not pursue or voluntarily support legal action against you in connection with it, subject to our compliance with applicable laws and legal obligations. To the extent your activity is conducted in accordance with this Policy, Phaidra considers it authorized under the Computer Fraud and Abuse Act (and analogous state laws), and Phaidra will not bring a claim under Section 1201 of the DMCA (17 U.S.C. § 1201) for good-faith security research conducted under this Policy.To qualify, your disclosure must be unconditional and must not involve extortion, threats, or any demand for payment.

This safe harbor applies only to the in-scope Information Systems; it does not extend to any out-of-scope, customer, or third-party system. This Policy does not authorize activity that is unlawful, and nothing in it limits Phaidra’s own legal obligations, including any obligation to notify customers, regulators, or authorities of an incident.

Changes to This Policy

We may change this Policy at any time by publishing a revised version and updating the date above. Vulnerabilities disclosed before an update remain subject to the Policy in effect at the time of disclosure.

PGP Key

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQINBGpan0ABEADTyAnpKhgUlyIVavsy+5g26Q6sqrnK3N5cA4FoUqfhxIm2n30s
1cPp0MD/OivRFhfVbU2a0Z6MEIx6pMMdMD48ZxumzFXvhDkRUYkCbPz9BkZaoxXy
MDgNpbQwEWCjS4ORmzO0ZfWe5hW8WLhfMzT9pxf4JT5ZNzk3sBtVyiGXAWXVNmxE
XAfFkFqIoEO1Rmz7zVpXpvqG4XC13EWUmhelaZMLvIb3BHEnlU9p8AyedD/JXurx
zQdJO2kXNRVONcJJnR+zPhdlI7IZgJbuPsGl8lPFnxTgafhFrQ3X1ni4C/Dmw6xm
xzDUFd1TkGOwnSeurJYdUty2CvsY5mNOVXe1KDJqPhiDHIqmDwgzfbxlJ0MEzm0g
OX77XNmvYqEJnXRy0Qtnn7pv6mKEVpyb9cNIojQHNXOQF/oW3OFZlLERudM1eC1d
do0UX3Fq4yLnpT0Uvr3of/allkLwQfZtN8DQ9py1IcoZh5+NBo0ZKoLA+gtegZRg
16/e9dcdccAdYPzC6koubORe2/1KewtyZHGdB+FQ7eBbF0SyWqW/+VFakMuvJJvR
i7MkAC4rbDkHkL2kbT1xhNuz9m6jpfhE03UAGmuWu74rOqdjbi1bf29H2kaQnWgF
3B131yDp9QE+HdYf5GKS3gHejdQjOcim9wurKzPRaY506V3JBmEPMh20+QARAQAB
tDFQaGFpZHJhIFZ1bG5lcmFiaWxpdHkgRGlzY2xvc3VyZSA8dmRwQHBoYWlkcmEu
YWk+iQJzBBMBCABdFiEEYg+8EsZuSMnI4/XczKSFw08fqFAFAmpan0AbFIAAAAAA
BAAObWFudTIsMi41KzEuMTIsMCwzAhsDBQkJZgGABQsJCAcCAiICBhUKCQgLAgQW
AgMBAh4HAheAAAoJEMykhcNPH6hQYjUQAItFJ/IbraIeZbxUl9WTWSiI1i3VU70g
dRnLGPvihEXhrG3uPEMmsCdNnHeJXi1GGF5dWuWyRsWbYRhoG8scVRc9UH12fxST
k4o1y4I7SX2MAc8ZDJtUktYn4IDI6qUT7cwN+epfquRd9KAxui5cmTL7+lbYPEll
8zxF8bwI1Bg3KfR9V3qowDzTCVQB7+QrViXq8SPZmU6YXVtPuqsoffSQ9HzOqxAt
v2LwfUzyLlB2UjUqO+yQDpiaQ7+955UfzFclgV2OSfl3/vApVNMrRaMoE1GPhPzY
ETCJiyF/94XS2FBYxB30ne94TbhAI0IHywkTnnBj0QqnbCBl/lhkVuIImgKNPOnL
cod5EZzt1Rh+ktpz/onaOzODcL6kqI2fFB8WuIzNu+wsBpbwV7WpV9TYn50KB2Ej
M6E/sIVpRkim6muMaZGPp9njhp4AaGXNnbLxyKY/NO+IO3kqLYP0d7V+Caulzkkr
453rG3BB3XKSTNGg8ND/Pco85SRBAm24XDfRIfVi2GVSk6QpzXAEEYS/leGYR/m8
FYP9lPwLVPEyy7PIi6ENBZKMKeeDMAOYdWBQC92DWg/HVIDgscvxIV6oLsV0B+ls
S8c9lcTBq1Y3iXivUIvV4eCA7zp5N5TmI6wNj2kiqLe5QgzQ7uArhyv+QAi4VqN/
y7sxXjp4290m
=hFIL
-----END PGP PUBLIC KEY BLOCK-----
Phaidra Logo
linkedin

Subscribe to our blog

Stay connected with our insightful systems control and AI content.

You can unsubscribe at any time. For more details, review our Privacy Policy page.

© 2026 Phaidra Inc. All Rights Reserved.
Alfred