← All legal pages

Disclosure

Vulnerability Disclosure

We welcome reports of suspected vulnerabilities in Enji Guard and related infrastructure. This page explains how to report and what to expect.

Reporting a vulnerability

If you believe you have found a vulnerability in Enji Guard or related Enji infrastructure, email [email protected]. Please include the affected URL, endpoint, repository, or component, a clear description, reproduction steps, and an impact assessment. Screenshots or logs are helpful.

Do not include secrets, customer data, or destructive payloads unless strictly necessary to demonstrate the issue.

In scope: Enji-operated services and infrastructure, such as our website, API, and GitHub App. Out of scope: customer-owned targets, third-party AI providers, and any testing prohibited below.

Safe-harbor expectations

When investigating, please do not:

  • Access, modify, delete, or exfiltrate other users’ data.
  • Run denial-of-service or load testing.
  • Use credential stuffing, phishing, or social engineering.
  • Install malware or attempt to maintain persistence.
  • Scan unrelated infrastructure.
  • Publicly disclose the issue before we have had a chance to respond.

Response

We make a best-effort attempt to acknowledge reports and investigate validated security issues. No bounty, reward, or payment is promised unless a separate written program is published.