Security
Vulnerability Disclosure
If you have found a problem in our system, we want to know about it before anyone else. We do not pursue people who report in good faith.
Last updated: 21 August 2026
How to report
Write to arlets@yesfor.ai. A useful report includes:
- what it concerns: URL, screen, request;
- what happens and what you expected;
- steps to reproduce it;
- the date and time when you tested it;
- how we can contact you.
What to expect from us
- Acknowledgement of your report within 3 business days.
- An initial assessment within 10 business days: whether we confirm it, how serious it is, when we will fix it.
- A notice when the problem has been fixed.
- Credit by name, if you want it. We do not publish names without consent.
We do not have a paid bounty program. If that changes, we will say so here.
What we ask you not to do
- Do not download, modify or delete other people’s data. One record as evidence is enough.
- Do not test denial of service or anything that degrades the service for others.
- Do not attempt social engineering against our people or vendors.
- Do not disclose the problem publicly before we have fixed it or before we have agreed on a date together.
- Do not test our clients’ systems. They belong to someone else, and we do not touch them without authorization either.
What we promise
If you act in good faith and according to the rules above, we will not take legal action against you or report the matter as an incident directed at us. If a third party brings a claim, we will confirm that you acted within this policy.