CoreLB is built to operate in customer production environments. Security is therefore central to how we build the platform. We welcome responsible disclosure of security vulnerabilities from researchers and customers.
If you believe you have identified a security issue in CoreLB, please report it to us. We will investigate and respond promptly.
1. How to Report
Send vulnerability reports to:
For sensitive reports, you may request a PGP key for encrypted communication by emailing us first.
2. What to Include
To help us investigate quickly, please include:
- A clear description of the vulnerability
- The potential impact if exploited
- Steps to reproduce the issue
- Any supporting material (screenshots, logs, proof-of-concept code)
- The environment or endpoint affected
- Your contact information for follow-up
The more detail you provide, the faster we can investigate and resolve the issue.
3. Scope
We welcome reports on vulnerabilities in:
- The CoreLB web application and API
- CoreLB platform infrastructure
- Authentication and access control mechanisms
- AI guardrails and policy enforcement
- Data isolation between customer tenants
- Credential handling and secrets management
- CoreLB integrations and agent components
4. Out of Scope
The following are generally out of scope:
- Vulnerabilities in third-party services or libraries not maintained by CoreLB
- Social engineering or phishing attacks against CoreLB employees
- Denial-of-service attacks against CoreLB systems
- Automated scanning without prior coordination
- Reports of missing security headers without a demonstrated impact
- Issues already known to us or previously reported
5. What to Expect
After you submit a report:
- We will acknowledge receipt within 3 business days
- We will investigate and aim to provide an initial assessment within 10 business days
- We will keep you informed of the status as we investigate
- We will notify you when the issue has been resolved
We do not currently offer a bug bounty program, but we are grateful to researchers who help improve the security of CoreLB.
6. Safe Harbor
We will not pursue legal action against security researchers who:
- Discover and report vulnerabilities in good faith
- Avoid accessing or modifying customer data
- Do not disrupt CoreLB services
- Do not exploit the vulnerability beyond what is necessary to demonstrate it
- Report the vulnerability to us before public disclosure
- Allow reasonable time for investigation and remediation before public disclosure
We ask that you give us sufficient time to investigate and address any issues before sharing them publicly.
7. Contact
All security reports should be sent to: [email protected]
For general security questions about the platform, see our Security Policy.