Skip to main content

Security & Disclosure Policy

Last updated: September 30, 2026

At Shipwright AI, the security of our users' codebase, data, and infrastructure is our highest priority. We believe that working with skilled security researchers across the globe is crucial in identifying weaknesses in any technology.

1. Scope

This policy applies to all systems and services managed by Shipwright AI, specifically including:

  • The Shipwright AI web application (shipwright.in and subdomains)
  • Shipwright AI REST APIs
  • Our backend code analysis and knowledge graph indexing engine
  • The Shipwright CLI tools

Out of scope: Any services hosted by third-party providers (e.g., AWS, GitHub, Stripe) where the vulnerability is in the provider's system rather than our implementation.

2. Safe Harbor

When conducting vulnerability research according to this policy, we consider this research to be:

  • Authorized in accordance with the Computer Fraud and Abuse Act (CFAA) (and/or similar state/international laws), and we will not initiate or support legal action against you for accidental, good faith violations of this policy.
  • Exempt from the Anti-Circumvention rules of the Digital Millennium Copyright Act (DMCA), and we will not bring a claim against you for circumvention of technology controls.

If legal action is initiated by a third party against you in connection with activities conducted under this policy, we will take steps to make it known that your actions were conducted in compliance with this policy.

3. Reporting Vulnerabilities

If you believe you have found a security vulnerability in one of our products or platforms, please send it to us by emailing:

Please include the following details in your report:
• A description of the vulnerability and its potential impact.
• Steps to reproduce the issue, including any required payloads or scripts.
• (Optional) Your name or handle for our future Hall of Fame.

4. Rules of Engagement

  • Do not execute any attacks that could harm the reliability/integrity of our services or data (e.g., DoS, DDoS).
  • Do not access, modify, or delete data belonging to other users. You must only interact with your own test accounts.
  • Do not use physical security attacks, social engineering, or phishing against Shipwright AI employees.
  • Do not publicly disclose the vulnerability until we have patched it. We aim to deploy patches for critical vulnerabilities within 48 hours.