Security

Vulnerability Disclosure Policy

Report security issues privately. We will coordinate a fix.

This programme covers Scalattice products operated by Robottik Ltd. There is no public bug bounty.

Report privately

Email support@scalattice.com. Do not open a public GitHub issue.

Safe harbour

Good-faith research that follows this policy will not be treated as an attack.

RFC 9116

Machine-readable contact is at /.well-known/security.txt on this site and on Scalattice Cloud.

Vulnerability Disclosure Policy

Last updated: 07/09/2026

This policy explains how to report a security vulnerability in Scalattice products operated by Robottik Ltd, registered in England and Wales (company no. 17193565). We welcome reports from independent researchers, customers, and providers.

We do not currently run a paid bug bounty. We will acknowledge valid reports and may credit researchers who wish to be named once a fix is live.

1. How to report

Do not file a public GitHub issue for a security problem.

Email support@scalattice.com.

Use a clear subject such as Scalattice security: [short summary]. Encrypt the message if you can; otherwise send in the clear rather than delaying the report.

Machine-readable contact: https://scalattice.com/.well-known/security.txt and https://scalattice.cloud/.well-known/security.txt.

2. What to include

Include as much of the following as you can:

  • A short description of the issue and why it matters
  • Affected product, host, URL, or repository, and the version or commit if known
  • The conditions needed to observe the issue (account type, request, or environment)
  • Impact: what an attacker could do if the issue is unfixed
  • Any logs, screenshots, or request identifiers that help us find it
  • Your preferred credit name, or a note that you want to remain anonymous

Do not include other people’s personal data, production secrets, or copies of customer prompts. If you obtained access to data you should not have, stop, describe what you saw at a high level, and delete local copies.

3. Scope

The canonical marketing site is scalattice.com. The same site is also served at scalattice.ai, scalattice.app, and scalattice.network.

In scope

  • scalattice.com and the marketing aliases above
  • Scalattice Cloud at scalattice.cloud
  • The inference API at api.scalattice.cloud
  • Authentication, sessions, API keys, credits, and provider payouts on those hosts
  • The open-source Scalattice agent and CLI
  • Official install scripts served from Scalattice Cloud

Out of scope

  • Denial of service, flooding, or load testing against production
  • Social engineering, phishing, or physical attacks on people or offices
  • Issues that only affect a provider’s own machine after it is already compromised
  • Findings in third-party products we use (for example Stripe, Cloudflare, or email delivery) unless they expose a Scalattice-specific misconfiguration
  • Missing security headers, SPF/DKIM, or cookie flags with no demonstrated impact
  • Self-XSS, logout CSRF, or clickjacking on pages that already refuse framing
  • Publicly known issues we have already patched, or reports that require an outdated browser

4. Rules of engagement

Stay within this policy:

  • Use your own test accounts. Do not access other people’s data.
  • Stop if you reach a system or dataset beyond what is needed to show the issue.
  • Do not modify, delete, or exfiltrate data. A minimal demonstration on an account you control is enough.
  • Do not degrade service for other users, providers, or the inference network.
  • Do not demand payment as a condition of reporting. We do not currently pay bounties.

5. What to expect

  1. Acknowledgement - we aim to confirm receipt within five business days.
  2. Triage - we assess severity, reproduce where we can, and say whether we accept the report.
  3. Fix - accepted issues are prioritised. Timing depends on impact and on whether a change must ship to Cloud, the API, the agent, or the marketing site.
  4. Disclosure - please wait until we have deployed a fix, or until we agree a date with you, before discussing the issue in public. We will not withhold credit unreasonably.

We may close reports that are out of scope, not reproducible, or already known. Duplicate reports are acknowledged; credit usually goes to the first valid report we can act on.

6. Safe harbour

Robottik Ltd will not pursue civil or criminal action against researchers who report issues in good faith and follow this policy, including staying in scope, avoiding privacy harm, and not disrupting the service. If a law-enforcement or third-party action arises from activity that complied with this policy, we will make that compliance known.

Safe harbour does not cover activity that is out of scope, that continues after we ask you to stop, or that is otherwise unlawful.

7. Changes

We may update this policy. The date at the top of this page is the current version. Reports are assessed against the policy in force when we receive them.

8. Contact

Questions or security reports: support@scalattice.com or the Support centre.
Scalattice is operated by Robottik Ltd, registered in England and Wales (company no. 17193565).