Vulnerability Disclosure Policy
LangGuard Inc. (“LangGuard”, “We”) takes the security of our website, platform and customers’ data seriously. If you believe you have found a security vulnerability in a LangGuard system, we want to hear from you. This policy explains how to report it, what we ask of you, and what you can expect from us.
How to Report a Vulnerability
Email security@langguard.ai. This is the same contact listed in our security.txt file.
Please include as much of the following as you can:
- A description of the vulnerability and its potential impact.
- The affected URL, endpoint, product or component.
- Step-by-step instructions, proof-of-concept code or screenshots that let us reproduce the issue.
- Any relevant request and response samples, with sensitive data removed.
- How we can contact you for follow-up questions.
Please do not include real customer data, credentials or other personal information in your report.
Scope
This policy applies to:
- The LangGuard website at langguard.ai and its subdomains.
- The LangGuard platform, including its web application.
- LangGuard’s public and customer-facing APIs.
The following are out of scope:
- Social engineering, phishing or other attacks against LangGuard employees, contractors or customers.
- Physical attacks against LangGuard offices or equipment.
- Denial-of-service attacks, and volumetric or load testing of any kind.
- Vulnerabilities in third-party services or products that we do not own or operate. Please report these to the relevant vendor.
- Automated scanner output submitted without a demonstrated, exploitable impact.
- Missing security headers or best-practice hardening that have no demonstrable security impact.
Ground Rules
When researching a potential vulnerability, please:
- Make a good-faith effort to avoid privacy violations, destruction of data, and interruption or degradation of our services.
- Only interact with accounts and data that you own or that you have explicit permission to access.
- Stop testing and report immediately if you gain access to customer data, credentials or other sensitive information. Do not retain, copy, modify or share it.
- Do not use a vulnerability to pivot into other systems, or to establish persistent access.
What You Can Expect From Us
- We will acknowledge your report within 5 business days.
- We will keep you informed as we investigate and update you on our progress, including when the issue is confirmed and when it has been fixed.
- We will work with you to understand and validate the report, and tell you if we decide it is not a vulnerability.
Safe Harbor
LangGuard will consider security research that is conducted in good faith and in accordance with this policy to be authorized. If you comply with this policy, we will not initiate or support legal action against you for the research, including under anti-hacking, anti-circumvention or terms-of-service provisions, and we will work with you to understand and resolve the issue quickly.
This safe harbor applies only to LangGuard’s own systems and to claims that LangGuard could bring. It does not bind third parties, and it does not apply to activity that is outside the scope of this policy or that violates applicable law. If legal action is initiated by a third party against you in connection with research that complied with this policy, we will make it known that your actions were conducted in compliance with it.
If you are unsure whether your planned research is within this policy, please ask us at security@langguard.ai before you begin.
Coordinated Disclosure
We ask that you give us a reasonable opportunity to investigate and fix a vulnerability before you disclose it publicly. Please do not publish or share details of the issue with others until we have confirmed that a fix is available, or until 90 days after your report, whichever comes first. If you believe a longer or shorter timeline is warranted, contact us and we will work with you on it.
Rewards
LangGuard does not currently operate a paid bug bounty program, and we do not offer monetary rewards for vulnerability reports. We are grateful for every report and will treat each one seriously.
Changes to This Policy
We may update this policy from time to time. The current version is always available at langguard.ai/security-policy.