Vulnerability Disclosure Policy

Last reviewed: June 26, 2026. Next review due: June 26, 2027.

How to report

Email security@multipliers.ai with the details of the issue. Please include:

  • A clear description of the vulnerability and the affected asset
  • Reproduction steps (request/response samples, screenshots, proof-of-concept code)
  • Expected vs. observed behavior
  • Your name + (optional) a reference URL we can credit

Acknowledgement within 24 hours for any reasonable report. We treat all reports confidentially and never share reporter information without explicit consent.

Scope

In-scope

  • multipliers.ai and all subdomains we operate
  • The Multipliers public API (/api/*) and public MCP servers
  • The Multipliers web application
  • Customer-managed VPC deployments of the Multipliers platform (please coordinate with the customer first)

Out of scope

  • Third-party platforms we connect to (report to those vendors directly)
  • Findings on customer-controlled credentials, even if discovered through Multipliers
  • Denial of service via volumetric load — please don't
  • Social engineering of Multipliers employees, customers, or vendors
  • Physical security of Multipliers offices
  • Findings that require already-compromised user accounts unless escalation is demonstrated
  • Self-XSS, missing security headers without a demonstrated impact, vulnerabilities in 3rd-party dependencies that we patch on a normal cadence

Safe harbor

We will not pursue legal action against, and will treat as authorized, any researcher who:

  • Makes a good-faith effort to comply with this policy
  • Avoids privacy violations, data destruction, and service interruption
  • Does not exploit a finding beyond the minimum needed to confirm the issue
  • Reports promptly and gives us reasonable time to remediate before public disclosure
  • Does not access, alter, or exfiltrate data belonging to other Multipliers customers

If your research follows this policy, we'll work with you to ensure quick resolution and a coordinated public disclosure when appropriate.

Disclosure timeline

Our standard remediation SLA, by CVSS severity:

  • Critical (CVSS ≥ 9.0): Triage within 24 hours, remediate within 7 days where technically possible.
  • High (CVSS 7.0–8.9): Triage within 72 hours, remediate within 30 days.
  • Medium (CVSS 4.0–6.9): Triage within 7 days, remediate within 90 days.
  • Low (CVSS < 4.0): Triage within 14 days; remediate on a best-effort basis.

We follow a 90-day disclosure window by default. If a fix is not feasible within 90 days, we will coordinate an extension with the reporter and document the rationale.

Recognition

Researchers whose reports lead to a remediated finding are credited (with consent) in our public acknowledgements. A formal bug bounty program is on our roadmap (Phase 4); we'll announce monetary rewards there once the program launches.

What you can expect from us

  • A reply within 24 hours (typically faster)
  • An assigned tracking ID and a single point of contact
  • Regular status updates (no less than every 14 days for the duration of triage + fix)
  • A post-fix summary describing the issue, root cause, and remediation
  • Public credit (with your consent) when a fix ships

Compliance + certifications

Multipliers' security posture is documented in our CISO-ready security canon (available on request — email contact@kiwana.ai). We are pursuing SOC 2 Type II + ISO 27001 (Phase 4); current state and the 13 secure-by-design first principles we operate against are catalogued there.

Contact