Platform Overview EAV-Graph Cognitive Brain 8 Operational Playbooks Dual-Plane Architecture Competitive Benchmark Pricing & ROI Engine CISO Trust Center Deploy In-VPC Sandbox

1. Responsible Disclosure & Safe Harbor Commitment

At dAutomata, the security of our deterministic coworker platform and our customers' VPC boundaries is paramount. We actively encourage responsible vulnerability research and coordinate closely with ethical hackers, independent researchers, and academic institutions.

Safe Harbor Protection: If you conduct vulnerability research in good faith and in compliance with this policy, dAutomata pledges that:

2. Reporting Procedures & PGP Encryption

Please send detailed vulnerability reports to our dedicated security engineering team at:
security@dautomata.com

When submitting reports involving sensitive reproduction payloads, please encrypt your email using our official PGP Public Key:

-----BEGIN PGP PUBLIC KEY BLOCK----- Version: OpenPGP.js v5.1.0 Comment: dAutomata Security Engineering Team <security@dautomata.com> mQENBF/h6cMBCAC7W6yG6vYQ4Fq6mZ9hX7t5vN8kL3yJ1pQ0wR2eT4uI6oP8 aS3dF5gH7jK9lZ1xX2c4vB6n8m0L9k8j7h6g5f4d3s2a1Q0wE9r8t7y6u5i4 o3p2a1s0d9f8g7h6j5k4l3z2x1c0v9b8n7m6L5k4j3h2g1f0e9d8c7b6a5Z4 Fingerprint: F1B4 9E82 C35A 77D0 4918 9B23 E842 1690 D7A3 C241 -----END PGP PUBLIC KEY BLOCK-----

3. Program Scope & Target Systems

In-Scope Targets:

Out-of-Scope Targets:

4. Bug Bounty Reward Matrix

We reward eligible, qualifying vulnerability reports based on CVSS v3.1 severity scores and real-world exploitability:

Severity Tier CVSS v3.1 Score Example Vulnerability Reward Range
Critical 9.0 – 10.0 Remote Code Execution (RCE) inside worker micro-VM, cross-tenant context leakage, CEL policy bypass allowing unauthorized API mutations. $2,500 – $10,000+
High 7.0 – 8.9 Privilege escalation within tenant workspace, authentication bypass on webhook ingress, sensitive credential extraction. $1,000 – $2,500
Medium 4.0 – 6.9 Stored Cross-Site Scripting (XSS) affecting tenant administrators, CSRF on state-changing operations, insecure direct object reference (IDOR). $250 – $1,000
Low 0.1 – 3.9 Informational disclosures, missing defense-in-depth headers without proven exploitability. Swag + Hall of Fame

5. Response Time Commitments (SLAs)

Our dedicated security incident response team adheres to strict communication SLAs:

6. Enterprise Technical Security Controls

For enterprise customers evaluating our security posture, dAutomata enforces the following technical baselines across our engineering stack: