Security
Security and vulnerability disclosure
How we protect the platform, and how to report a vulnerability responsibly.
Last updated: To confirm: publication date
01Our approach
Access controls, an audit trail of approvals and changes, and a choice of deployment options. The security pack, covering architecture, access controls, incident response and single sign-on detail, is shared after a mutual NDA; request it from the Trust page.
02Report a vulnerability
Email sales@embernest.ai with a description, steps to reproduce and any proof of concept. To confirm: dedicated security address and PGP key, if used
- Give us reasonable time to fix the issue before you disclose it.
- Do not access, change or delete data that is not yours, and do not degrade the service.
- Do not run tests that need social engineering, physical access or denial of service.
03What to expect from us
To confirm: acknowledgement and triage times, whether a safe-harbour statement applies, and whether rewards are offered
04Certifications and frameworks
We make no certification claim until it has been awarded. To confirm: list frameworks only once confirmed