Skip to content
Private preview — Design partners are now being selected for controlled agent-execution pilots. Apply now
Responsible Disclosure

Vulnerability Disclosure Policy

How to report security issues in the DecisionHypervisor™ platform — what is in scope, what is prohibited, and what researchers can expect back.

DOC-VDP-001 · v1.0.0 · Effective 2026-07-23 · Review status: Internal Review

Scopedecisionhypervisor.com, its API endpoints, and the DecisionHypervisor runtime interfaces made available to design partners.

Out of scopeThird-party services and subprocessors, customer deployments, environments operated by design partners, and physical infrastructure.

Prohibited testingDo not access data beyond what is necessary to demonstrate the issue, and do not disrupt service for others. Social engineering, denial-of-service testing, spam, and physical testing are prohibited.

How to reportEmail security@decisionhypervisor.com with a description, reproduction steps, and potential impact.

Response targetsWe aim to acknowledge reports within two business days and to provide a remediation assessment or timeline within ten business days.

Good-faith researchWe ask researchers to follow this policy, avoid data access beyond what is necessary to demonstrate the issue, and avoid disrupting service for others. Formal safe-harbor terms are under counsel review and will be published here once approved.

Coordinated disclosurePlease do not disclose an issue publicly until we have had a reasonable opportunity to respond, and coordinate disclosure timing with us where possible.

Also published atThis policy is referenced by /.well-known/security.txt and summarized on the security principles page.

Security reports are handled directly by the DecisionHypervisor engineering team.

Report a vulnerability →
Request a Control Pilot