Security Policy

Version 2026-01 · Last updated January 15, 2026

If you have found a security issue in Inside The Credit AI, we want to hear about it. This page tells you how to report it and what we commit to in return.

Reporting

Email security@insidethecreditai.com. Include enough detail to reproduce the issue: the URL or endpoint, the steps, and what you observed. If you can, include the request id from the response header — it leads straight to the relevant logs.

Please do not include another person’s data in your report. If you have accessed data that is not yours, tell us what you accessed rather than sending it to us.

Our commitments

  • We acknowledge reports within 2 business days.
  • We give an initial assessment within 5 business days.
  • We keep you updated while we work on a fix, and tell you when it ships.
  • We credit you publicly if you would like us to, and respect your preference if you would not.

Safe harbour

We will not pursue or support legal action against anyone who makes a good-faith effort to comply with this policy. If a third party brings action against you for research conducted under this policy, we will make it known that your actions were authorized.

Good faith means:

  • Testing only against accounts you own or have explicit permission to test.
  • Stopping as soon as you have confirmed a vulnerability, rather than exploring how far it goes.
  • Not accessing, modifying, exfiltrating or destroying data that is not yours.
  • Not degrading the service for other members.
  • Giving us reasonable time to fix an issue before disclosing it publicly.

In scope

  • The insidethecreditai.com web application and its API.
  • Authentication, session handling and multi-factor authentication.
  • Authorization, including any cross-account data access.
  • Injection of any kind, including prompt injection that reaches data or actions it should not.
  • Business logic flaws with a security consequence.
  • Exposure of sensitive data in responses, logs or error messages.

Out of scope

  • Denial of service, volumetric or resource-exhaustion testing.
  • Social engineering of our staff, members or vendors.
  • Physical attacks against our offices or personnel.
  • Findings from automated scanners without a demonstrated impact.
  • Missing best-practice headers with no demonstrated exploit path.
  • Vulnerabilities in third-party services we do not control — report those to the vendor.
  • Self-XSS, or issues requiring a compromised device or a physically present attacker.

What we consider severe

The findings we care most about, in order: anything that lets one member read or modify another member’s credit data; anything that bypasses authentication or multi-factor authentication; anything that extracts identity data or credentials; and anything that causes the AI layer to reach data or an action outside the requesting member’s scope.

Rewards

We do not currently run a paid bug bounty. We will credit researchers who want it, and we will say so plainly rather than implying a reward that does not exist. If we launch a bounty programme, this page will be updated with its terms.