The Regulator.ai team takes security seriously. We appreciate your efforts to responsibly disclose security vulnerabilities.
Please do not report security vulnerabilities through public GitHub issues.
Instead, please report security vulnerabilities by email to: security@ai.ventures
We strive to respond to security reports promptly:
- 24 hours: Initial acknowledgment of your report
- 72 hours: Assessment and preliminary response with severity classification
- 7 days: Detailed response with remediation timeline
- 30 days: Resolution target for critical vulnerabilities
Please include the following information in your report:
- Vulnerability Description: Clear description of the security issue
- Steps to Reproduce: Detailed steps to reproduce the vulnerability
- Impact Assessment: Your assessment of the potential impact
- Suggested Fix: If you have ideas for how to fix the issue
- Supporting Materials: Screenshots, logs, or proof-of-concept code
- Your Contact Information: So we can follow up with questions
We provide security updates for the following versions:
| Version | Supported |
|---|---|
| 1.x.x | ✅ Yes |
| 0.x.x |
When using Regulator.ai:
- Always use the latest stable version
- Keep your dependencies up to date
- Use secure configuration settings
- Follow our security guidelines in the documentation
- Implement proper authentication and authorization
- Regularly audit your compliance configurations
We are planning to launch a bug bounty program soon. Stay tuned for updates!
- We ask that you give us reasonable time to investigate and fix security issues before public disclosure
- We will acknowledge your contribution in our security advisories (with your permission)
- We follow responsible disclosure practices and will coordinate with you on timing
Regulator.ai includes several built-in security features:
- Encryption: All data in transit and at rest is encrypted
- Authentication: Multi-factor authentication support
- Authorization: Role-based access control (RBAC)
- Audit Logging: Comprehensive audit trails
- Compliance: SOC 2 Type II, GDPR, and other frameworks
For security-related questions or concerns:
- Email: security@ai.ventures
- GPG Key: Available upon request
Thank you for helping keep Regulator.ai secure!