We welcome reports from security researchers. This policy explains what is in scope, how to report a vulnerability, and what you can expect from us in return.
This policy covers the Human Signal Index web application, its public API endpoints, and its authentication flows. If you are unsure whether something is in scope, ask before you test.
If you make a good-faith effort to follow this policy, we will not pursue or support legal action against you for your research. We consider activity conducted under this policy to be authorized. If a third party brings action against you for work that followed this policy, we will make that authorization known.
Please give us a reasonable chance to fix an issue before you discuss it publicly — 90 days is a good default. We are happy to coordinate a disclosure date and to credit you for the finding if you would like that.
Security reports: security@amenxlabs.com. For misconduct or abuse rather than a technical flaw, use the whistleblower center.