Vulnerability Disclosure Programme
Version: v1.0 — 2026-07-23 Effective date: 2026-07-23
Vestibo ("Vestibo") welcomes reports from security researchers. This page is our public vulnerability disclosure programme. It is not a paid bug bounty (see § 6), but we commit to acknowledging every good-faith report and to working with researchers under a clear safe-harbour.
1. Scope
In scope:
*.vestibo.com(marketing site, dashboard, public agent profiles, marketplace, status page)- the embeddable widget served from our infrastructure
- the public REST API (served under
https://app.vestibo.com/api) - the deployed agent runtime (only against an agent you control, in a tenant you own)
Out of scope:
- third-party services and sub-processors (report directly to that
vendor — see
SUBPROCESSORS.md); - social-engineering attacks against Vestibo employees, contractors, or customers;
- physical attacks against Vestibo facilities or staff;
- denial-of-service testing of any kind without prior written coordination;
- testing against tenants you do not own — this includes cross-tenant probing on the multi-tenant infrastructure;
- automated scanning that generates >10 requests per second to any endpoint;
- findings that depend on outdated browsers (>2 major versions behind current) or jailbroken devices;
- reports about missing security headers without a demonstrated exploit;
- reports about the lack of rate limiting on non-authentication endpoints without a demonstrated exploit;
- reports about SPF/DKIM/DMARC posture without a demonstrated spoofing exploit.
2. Rules of engagement
When testing, you agree to:
- act in good faith and only as necessary to demonstrate the finding;
- not disrupt or degrade the Service for other customers;
- not access, modify, or exfiltrate data you do not own (use a test tenant); if you inadvertently access another tenant's data, stop immediately and report it;
- not use vulnerabilities to pivot to other systems or to maintain persistent access;
- give Vestibo a reasonable opportunity to remediate before any public disclosure;
- comply with all applicable laws, including export controls and the Computer Fraud and Abuse Act.
3. How to report
Email findings to security@vestibo.com. If you would like to encrypt
your report, request our current PGP key at that address. Our
security.txt file (per RFC 9116), at
https://vestibo.com/.well-known/security.txt, is the canonical source
of our security contact and policy URLs.
Include:
- a clear description of the finding and its impact;
- step-by-step reproduction (curl / HTTP request preferred);
- the affected URL, endpoint, or component;
- a proof of concept where applicable;
- your contact details and whether you want public credit.
4. What we will do
- Acknowledge within two (2) business days.
- Triage with an initial severity assessment within five (5) business days.
- Remediate on a timeline that matches severity:
- critical: target ≤ 7 days
- high: target ≤ 14 days
- medium: target ≤ 60 days
- low / informational: target ≤ 90 days
- Keep you updated at least every two (2) weeks until close.
- Credit you publicly, with your permission, unless you ask to remain anonymous.
5. Safe harbour
If you make a good-faith effort to comply with this policy, Vestibo will:
- not pursue or support any legal action related to your research;
- consider your activity authorised under the Computer Fraud and Abuse Act, the DMCA anti-circumvention provisions, and the Vestibo Acceptable Use Policy;
- consider the activity exempt from restrictions in our Terms of Service that would otherwise prohibit it.
This authorisation extends only to acts within the scope and rules above. We cannot grant authorisation for activities against third-party services or our sub-processors.
If a third party initiates legal action against you for research conducted in compliance with this policy, we will take reasonable steps to make it known that the activity was authorised.
6. Bounty
There is currently no monetary bounty. We may, in our discretion, send a thank-you (swag, conference passes, or similar) for exceptional reports. We will move to a paid bounty programme as the company matures; watch this page for an announcement.
7. Contact
| Subject | Address |
|---|---|
| Vulnerability reports | security@vestibo.com |
| Already-disclosed CVE / fix coordination | security@vestibo.com |
security.txt | https://vestibo.com/.well-known/security.txt |
Changelog
- v1.0 (2026-07-23) — first published version; rebranded to Vestibo and reconciled to the current product.
- v0.1 (2026-05-16) — initial internal draft.