If you have found a security flaw, we want to hear about it, and we will not pursue you for finding it in good faith.
Green Package Pro LLC · Version 1.0.0 · Effective August 4, 2026
If you make a good-faith effort to comply with this policy, we will not initiate or support legal action against you for your research. We consider such research authorised, we will not report you to law enforcement for it, and if a third party brings action against you for activity conducted in accordance with this policy, we will make it known that your actions were authorised.
If you are unsure whether something is in scope or whether a particular test is acceptable, ask us before you do it. We would much rather answer a question than have you guess.
Email [email protected]. Please include enough detail for us to reproduce the issue: the URL or component affected, the steps you took, what you expected, and what actually happened. A proof of concept, a screenshot, or a short recording all help. Write in English if you can; if that is difficult, send it in your own language and we will translate.
Please report even if you are not certain it is exploitable. A partial finding we can investigate is more useful than a perfect report that never arrives.
| Stage | Our target |
|---|---|
| Acknowledge your report | Within 3 business days |
| Confirm whether we can reproduce it, and its severity | Within 10 business days |
| Keep you updated while we work on it | At least every 14 days until resolved |
| Fix a critical or high-severity issue | As fast as we safely can — typically days, not weeks |
| Tell you when it is fixed | Always |
These are targets we hold ourselves to, not contractual guarantees. We are a small team; if something takes longer we will tell you why rather than going quiet.
We are glad to credit you publicly by name or handle when the issue is resolved, if you want that. Tell us how you would like to be named, or tell us you would rather stay anonymous. We do not currently run a paid bug bounty and cannot offer a monetary reward — we would rather say that up front than let you spend a weekend expecting one.
The websites and services we operate, including eyesinai.com and its subdomains, the client portal, the embeddable assistant widget, and our public API endpoints.
Some things are either not ours to authorise or not useful to receive. Please do not test or report:
To stay within the safe harbour above, please:
A machine-readable pointer to this policy is served at /.well-known/security.txt, following the standard convention so automated tooling and researchers can find the right contact without guessing.
Every published version of this document. The full corpus history is at changelog.
| Version | Effective | What changed |
|---|---|---|
| 1.0.0 | August 4, 2026 | Initial publication. Adds a safe-harbour commitment for good-faith research, response targets, and scope boundaries. Supersedes the bare .well-known/security.txt contact. |
Questions about this document? Email [email protected].