Vulnerability Disclosure Policy
Last reviewed: June 26, 2026. Next review due: June 26, 2027.
How to report
Email security@multipliers.ai with the details of the issue. Please include:
- A clear description of the vulnerability and the affected asset
- Reproduction steps (request/response samples, screenshots, proof-of-concept code)
- Expected vs. observed behavior
- Your name + (optional) a reference URL we can credit
Acknowledgement within 24 hours for any reasonable report. We treat all reports confidentially and never share reporter information without explicit consent.
Scope
In-scope
multipliers.aiand all subdomains we operate- The Multipliers public API (
/api/*) and public MCP servers - The Multipliers web application
- Customer-managed VPC deployments of the Multipliers platform (please coordinate with the customer first)
Out of scope
- Third-party platforms we connect to (report to those vendors directly)
- Findings on customer-controlled credentials, even if discovered through Multipliers
- Denial of service via volumetric load — please don't
- Social engineering of Multipliers employees, customers, or vendors
- Physical security of Multipliers offices
- Findings that require already-compromised user accounts unless escalation is demonstrated
- Self-XSS, missing security headers without a demonstrated impact, vulnerabilities in 3rd-party dependencies that we patch on a normal cadence
Safe harbor
We will not pursue legal action against, and will treat as authorized, any researcher who:
- Makes a good-faith effort to comply with this policy
- Avoids privacy violations, data destruction, and service interruption
- Does not exploit a finding beyond the minimum needed to confirm the issue
- Reports promptly and gives us reasonable time to remediate before public disclosure
- Does not access, alter, or exfiltrate data belonging to other Multipliers customers
If your research follows this policy, we'll work with you to ensure quick resolution and a coordinated public disclosure when appropriate.
Disclosure timeline
Our standard remediation SLA, by CVSS severity:
- Critical (CVSS ≥ 9.0): Triage within 24 hours, remediate within 7 days where technically possible.
- High (CVSS 7.0–8.9): Triage within 72 hours, remediate within 30 days.
- Medium (CVSS 4.0–6.9): Triage within 7 days, remediate within 90 days.
- Low (CVSS < 4.0): Triage within 14 days; remediate on a best-effort basis.
We follow a 90-day disclosure window by default. If a fix is not feasible within 90 days, we will coordinate an extension with the reporter and document the rationale.
Recognition
Researchers whose reports lead to a remediated finding are credited (with consent) in our public acknowledgements. A formal bug bounty program is on our roadmap (Phase 4); we'll announce monetary rewards there once the program launches.
What you can expect from us
- A reply within 24 hours (typically faster)
- An assigned tracking ID and a single point of contact
- Regular status updates (no less than every 14 days for the duration of triage + fix)
- A post-fix summary describing the issue, root cause, and remediation
- Public credit (with your consent) when a fix ships
Compliance + certifications
Multipliers' security posture is documented in our CISO-ready security canon (available on request — email contact@kiwana.ai). We are pursuing SOC 2 Type II + ISO 27001 (Phase 4); current state and the 13 secure-by-design first principles we operate against are catalogued there.
Contact
- Email:
security@multipliers.ai - RFC 9116 file:
/.well-known/security.txt - Severe issues requiring direct response: include
[URGENT]in the subject line