Last updated September 9, 2026
AI Reserve (operated by Audacity Advisory Corp) welcomes good-faith security research. If you believe you have found a vulnerability in our services, we want to hear about it, we will respond, and we will not take legal action against research that follows this policy.
In scope — the services we operate:
Out of scope:
Never access customer data that is not yours.
If a proof of concept unexpectedly exposes another organization's data, stop immediately, capture the minimum needed to describe the issue, and report it — do not download, retain, or share it.
Email security@aireserve.com with:
You may request an encrypted channel in your first mail and we will arrange one. Please give us a reasonable opportunity to remediate before public disclosure; we ask for coordinated disclosure and will agree on a timeline with you (our default request is 90 days).
Reports are triaged by our security lead, tracked internally, and remediated through our normal reviewed-and-gated change process.
We consider security research conducted in line with this policy to be authorized, and we will not initiate legal action or law-enforcement referral against you for it. Specifically, for good-faith research within scope: we waive claims under the Computer Fraud and Abuse Act (and equivalent laws) and under anti-circumvention provisions of the DMCA to the extent your research would otherwise violate them, and we will state that your access was authorized if a third party raises the question. This safe harbor does not extend to actions outside this policy — accessing or retaining customer data beyond the minimum proof, degrading the service, or extortion voids it.
We do not currently operate a paid bug bounty. We are a small company and we say so plainly rather than implying rewards we do not pay. What we do offer: a genuine, fast human response; credit by name (with your consent) in the remediation change and, where meaningful, on this page; and our thanks. If we later adopt a paid program, this policy will be updated and the change announced here.