Vulnerability Disclosure Policy

Last updated September 2, 2026

Agencies run their clients' social accounts on Aidelly, so a vulnerability here can affect people who never signed up with us. If you have found one, we would rather hear from you than not. This page says how to reach us, what we will do, and what we promise not to do.

How to report

Email security@aidelly.com. Our machine-readable contact is published at /.well-known/security.txt.

A useful report includes what you found, where, and enough detail for us to reproduce it. A proof of concept helps. Tell us what you think the impact is, even roughly. If you are not sure whether something is a real issue, send it anyway.

What we commit to

  • We acknowledge your report within 3 business days, from a human, not an autoresponder.
  • We give you an initial assessment and an indication of severity within 10 business days.
  • We keep you updated while we work on it, and we tell you when it is fixed.
  • We will credit you publicly if you want that, and stay quiet about your involvement if you prefer.
  • We will not bill you, threaten you, or ask you to sign anything before we will read your report.

We do not currently run a paid bug bounty. If that changes we will say so here rather than leaving you to ask.

Safe harbour

If you make a good-faith effort to follow this policy, we will treat your research as authorised. We will not pursue or support legal action against you, and if a third party brings action against you for work that followed this policy, we will make it known that your research was authorised.

Good faith means you gave us reasonable time to respond before telling anyone else, you did not access or modify data belonging to anyone other than yourself, and you stopped as soon as you had enough to write the report.

Please do not

  • Access, change, or delete data belonging to another customer. If a flaw exposes someone else's data, stop and describe it rather than collecting it.
  • Run denial of service, load, or brute-force testing against our systems.
  • Use social engineering, phishing, or physical attempts against our team, our customers, or our vendors.
  • Test the social platforms we integrate with. They are not ours, and their own disclosure policies apply.
  • Publish details before we have had a chance to fix the issue.

In scope

The Aidelly application at app.aidelly.ai, the marketing site at www.aidelly.ai, our public API and MCP server, and white-label deployments running on customer domains.

Out of scope: the social platforms themselves, our vendors' own infrastructure, and findings that amount to missing hardening with no demonstrated impact. Reports generated by an automated scanner with no analysis attached are usually not actionable, though we will still read them.

Coordinated disclosure

We aim to fix issues before they are made public, and we would rather agree a timeline with you than impose one. If we disagree about severity or timing, tell us. We would rather have that conversation than have you publish because we went quiet.

Contact

security@aidelly.com

Aidelly Corporation, a Delaware corporation. 8 The Green STE B, Dover, DE 19901.