Compliance
Responsible Disclosure Policy
Last updated: July 2026
1. Purpose and Introduction
INTELLIGENCE AI LTD is committed to protecting the security and privacy of our customers, users, and systems. We value the work of the security research community and recognise that responsible disclosure of vulnerabilities is an essential part of maintaining a secure platform.
This Responsible Disclosure Policy tells you how to report security vulnerabilities to us, what we expect from researchers, and what you can expect from us in return. It is designed to operate consistently with UK law, including the Computer Misuse Act 1990, the Data Protection Act 2018, and UK GDPR, and to align with industry best practice for coordinated vulnerability disclosure.
If you follow this policy when reporting a vulnerability in good faith, we will not take legal action against you or ask law enforcement to investigate you for the actions described in this policy.
2. Scope and Systems in Scope
2.1 In-scope systems
This policy applies to vulnerabilities in systems, applications, websites, and services owned or operated byINTELLIGENCE AI LTD, including:
- Our public-facing marketing website and any subdomains that we control
- Our no-code automation platform, its dashboard, APIs, and user interfaces
- Our authentication, account management, and billing flows, including integrations with Stripe checkout
- Cloud infrastructure, databases, and services under our direct control
- Mobile-responsive versions and any authenticated customer portals that we operate
2.2 Out-of-scope systems
The following are generally out of scope unless you have our prior written authorisation:
- Third-party websites, platforms, or services not owned or operated by us (for example, Stripe's own payment pages, social media sites, or integration partners)
- Physical security, social engineering, or phishing attacks against our staff or customers
- Denial-of-service attacks that degrade or disrupt services for other users
- Vulnerabilities in third-party software, plugins, or open-source libraries, unless they directly affect our services and you report them to us with relevant technical detail
- Brute-force attacks against user credentials, live customer accounts, or production authentication systems
- Any system or data that you are not authorised to access
Where you identify a vulnerability in a third-party service (for example, Stripe's hosted payment interface), we ask that you report it directly to that provider in accordance with their responsible disclosure policy. You may also inform us so that we can take any appropriate internal action.
3. Our Commitment to Researchers (Safe Harbour)
We will treat vulnerability reports seriously and respond promptly. Provided that you comply with the rules set out in this policy and act in good faith, we commit to:
- Not pursue, support, or authorise any legal action against you for activities that comply with this policy
- Work with you to understand, validate, and, where appropriate, remediate the reported vulnerability
- Acknowledge receipt of your report within 72 hours of submission, where possible
- Provide an initial assessment of the report's validity and severity within a reasonable timeframe
- Notify you when the vulnerability has been remediated or when we have decided not to take further action
- Give you appropriate public credit if you request it and we agree to disclose the finding, unless you prefer to remain anonymous
This safe harbour does not apply to activities that are unlawful, reckless, or outside the scope of this policy. It does not grant permission to test systems that belong to third parties without their consent.
4. Rules for Responsible Research
To ensure that your research is lawful, safe, and useful, please follow these rules at all times:
- Only test against systems and accounts that you own, or that we have explicitly authorised you to test
- Do not access, modify, delete, or exfiltrate data that does not belong to you
- If you accidentally access non-public data, stop immediately, do not retain copies, and notify us in your report
- Do not perform actions that could harm our services, infrastructure, or users, including denial-of-service attacks, spam, or large-scale automated scanning that degrades performance
- Do not install malware, backdoors, or persistent access mechanisms
- Do not exploit a vulnerability beyond what is necessary to demonstrate it safely
- Do not publicly disclose, share, or otherwise publish details of a vulnerability until we have remediated it or agreed a coordinated disclosure timeline with you
- Do not request financial rewards or compensation as a condition of disclosing a vulnerability; we may offer recognition at our discretion
- Do not test in ways that could violate UK GDPR, the Computer Misuse Act 1990, the Data Protection Act 2018, or any other applicable law
We encourage you to create a dedicated test account where possible. Do not test using accounts, data, or credentials belonging to our customers or employees.
5. How to Report a Vulnerability
Reports should be submitted through the contact page on our website, or by email at info@intelligenceailtd.com. If the report contains sensitive information, please use encryption where available or clearly mark the subject line as "Responsible Disclosure".
A good vulnerability report should include:
- A clear description of the vulnerability and the potential impact
- The affected URL, system, endpoint, or asset
- Step-by-step instructions that allow us to reproduce the issue
- Proof-of-concept code, screenshots, or a video, if helpful and safe to share
- The tools, browser, or operating system used, if relevant
- Your contact details and whether you would like to be publicly credited
- Any suggested remediation, if you have one
The more detail you provide, the faster and more accurately we can assess the report. Reports that are vague or cannot be reproduced may take longer to investigate.
6. What Happens After You Report
6.1 Acknowledgement and triage
We aim to acknowledge receipt of your report within 72 hours. We will then triage the report to confirm whether it is in scope, valid, and reproducible.
6.2 Investigation and remediation
Once a vulnerability is confirmed, we will assess its severity and prioritise remediation based on risk. We may contact you for additional information. We aim to remediate critical vulnerabilities as quickly as possible, and we will keep you informed of progress.
6.3 Disclosure
We prefer coordinated disclosure. Once a fix has been deployed and verified, we may publish a short summary of the issue and credit the researcher, with their permission. If you would like to remain anonymous or not be credited, please let us know.
6.4 Reports we decline to act on
We may decline to act on reports that are out of scope, based on unsupported claims, relate to accepted risk or configuration choices, or concern third-party systems outside our control. We will explain our decision where possible.
7. Exclusions and Limitations
This policy does not authorise any activity that is illegal under UK or applicable law. It does not grant permission to access systems, data, or accounts that you are not otherwise authorised to access. Researchers remain responsible for their own actions and must comply with all applicable laws, including the Computer Misuse Act 1990, UK GDPR, and the Data Protection Act 2018.
This policy does not create any contractual relationship between you and INTELLIGENCE AI LTD. We reserve the right to change, suspend, or revoke this policy at any time. If we become aware of conduct that is inconsistent with this policy, the safe harbour protections may not apply.
8. Relationship to Stripe and Third-Party Providers
Payment processing on our platform is handled by Stripe, Inc. Stripe maintains its own security, bug bounty, and responsible disclosure programmes. If you discover a vulnerability in Stripe's systems, payment pages, or APIs, please report it directly to Stripe in accordance with its policies. You can find more information at stripe.com.
We are not responsible for the security of third-party services, and this policy does not authorise testing against them. If you are unsure whether a system is within scope, please contact us before testing.
9. Recognition and Rewards
We are grateful to security researchers who help us improve our security. While we do not operate a formal bug bounty programme at this time, we may acknowledge researchers who report valid, in-scope vulnerabilities and who work with us to resolve them. Recognition may take the form of a public thank-you on our website, a credit in a security advisory, or another form of appreciation, at our discretion and with your consent.
10. Severity Assessment and Prioritisation
When we assess a vulnerability, we consider factors such as the likelihood of exploitation, the sensitivity of the data or systems affected, the potential impact on our users and services, and whether any mitigations are already in place. We use this assessment to prioritise remediation.
- Critical: Vulnerabilities that could allow widespread unauthorised access, disclosure of large volumes of sensitive data, remote code execution, or severe service disruption. We aim to investigate and take immediate action on the same or next business day.
- High: Vulnerabilities that could lead to significant data exposure, privilege escalation, or meaningful impact on service integrity. We aim to provide an initial response within 72 hours and remediate as quickly as practicable.
- Medium: Vulnerabilities with limited impact or requiring specific conditions to exploit. We aim to triage and provide a remediation plan within a reasonable timeframe.
- Low / Informational: Issues that pose minimal direct risk, such as missing security headers, weakly configured but non-exploitable services, or general hardening recommendations. We may address these through routine maintenance or accept them as residual risk.
11. Coordinated Disclosure Timeline
We support coordinated disclosure. Unless we agree otherwise in writing, we ask researchers to allow us a reasonable period to investigate, develop, and deploy a fix before any public disclosure. Our default disclosure timeline is set out below, although complex vulnerabilities may require additional time:
- Initial acknowledgement: within 72 hours of receiving a clear report
- Initial triage and severity assessment: within 7 days
- Remediation target: within 90 days for critical and high-severity issues, subject to complexity
- Publication of an advisory or credit: after the fix has been verified and deployed, and with the researcher's consent
If you believe a vulnerability is being actively exploited in the wild, or if you have information about an imminent threat, please indicate this clearly in your report so that we can prioritise accordingly.
12. Security Incident Management
Reports that indicate an active security incident, ongoing unauthorised access, or a data breach may trigger our internal incident response process. This process includes containment, evidence preservation, impact assessment, notification to affected parties where required by law (including UK GDPR breach notification obligations), and cooperation with law enforcement or regulators where appropriate.
If you discover evidence that suggests a breach of personal data or ongoing malicious activity, please include as much detail as possible while respecting privacy and legal obligations. Do not attempt to access, download, or retain personal data belonging to others.
13. Legal Notice and Relationship with Law Enforcement
This policy is intended to promote responsible security research and to provide a lawful framework for researchers who act in good faith. Nothing in this policy authorises any person to commit an offence under the Computer Misuse Act 1990, the Data Protection Act 2018, UK GDPR, or any other applicable legislation.
We will not voluntarily refer a researcher to law enforcement for activity that complies with this policy and is carried out in good faith. However, we reserve the right to cooperate with law enforcement, regulators, or court orders where required by law, and we will take appropriate action against any person who acts outside the scope of this policy or causes harm to our users, systems, or business.
14. Policy Review and Feedback
We review this Responsible Disclosure Policy regularly to ensure that it remains clear, fair, and aligned with UK law and industry best practice. Researchers and members of the public are welcome to provide feedback on the policy itself. Updates will be posted on this page with a revised "Last updated" date.
15. Questions and Contact
If you have any questions about this Responsible Disclosure Policy, are uncertain whether a particular system is in scope, or would like to report a vulnerability, please contact us via the contact page on our website, or by email at info@intelligenceailtd.com.