Visible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot nowVisible Amsterdam: Join us on September 3 for an exclusive afternoon exploring the future of AI Search. Request your spot now
Promptwatch Logo

Security Disclosure

Last updated:

Introduction

Promptwatch takes the security of its products and services seriously. We appreciate the work of security researchers who help us identify and remediate vulnerabilities, and we want to make it easy and safe for you to do so. This policy describes the rules for reporting a vulnerability you have discovered.

Legal posture and safe harbour

Promptwatch will not pursue legal action against researchers who report vulnerabilities in good faith, stay within the scope of this policy, do not access or modify data beyond what is needed to demonstrate the issue, and respect the disclosure timeline. Security research conducted in accordance with this policy is considered authorised, including limited reverse engineering where strictly necessary to identify and demonstrate a vulnerability. You must comply with all applicable laws at all times; this policy does not authorise activity that violates the law or the rights of third parties.

Terms and conditions

  • Do not publicly disclose the vulnerability until Promptwatch has had a reasonable opportunity to investigate and remediate (typically 90 days from the date of the report).

  • Do not access, modify, exfiltrate, or destroy data of Promptwatch or its customers.

  • Do not perform testing that disrupts the service for other users (no DoS, no automated scanning at rates that affect performance).

  • Do not test customer environments without their explicit prior consent.

  • Reports must be submitted in English and contain enough detail to reproduce the issue.

How to submit a vulnerability

Send your report to [email protected]. Include:

  • A clear description of the vulnerability and its impact.

  • Step-by-step instructions to reproduce, including any proof-of-concept code, screenshots, or videos.

  • The affected URL / endpoint / product and version where applicable.

  • Your contact details if you would like to receive updates and be credited.

What you can expect from us

  • An acknowledgement of your report within 5 working days.

  • An assessment and a target remediation timeline within 10 working days.

  • Status updates as we investigate and fix the issue.

  • Public credit if you wish (subject to your preference).

Promptwatch does not currently operate a monetary bug bounty program. We do not offer financial rewards for vulnerability reports, but we are happy to publicly acknowledge researchers who report valid issues in good faith.

Acceptance criteria and prioritisation

We triage reports based on severity and practical impact, using a simple low / medium / high / critical scheme informed by CVSS. Critical and high severity issues (e.g. remote code execution, authentication bypass, cross-tenant data access) are prioritised for immediate remediation; lower severity issues are scheduled into our regular release cycle.

We typically do not accept reports of:

  • Theoretical issues without a practical, demonstrable impact.

  • Missing best-practice headers or configuration flags without a demonstrated exploit path.

  • Output from automated scanners without a validated proof of concept.

  • Social engineering, phishing, or physical attacks against Promptwatch employees or infrastructure.

  • Denial-of-service, rate limiting, or brute-force issues.

  • Vulnerabilities in third-party services outside of Promptwatch's control.

Contact

If you have any questions about this policy, you can contact us by email: [email protected]