Disclosure
Vulnerability Disclosure
We welcome reports of suspected vulnerabilities in Enji Guard and related infrastructure. This page explains how to report and what to expect.
Reporting a vulnerability
If you believe you have found a vulnerability in Enji Guard or related Enji infrastructure, email [email protected]. Please include the affected URL, endpoint, repository, or component, a clear description, reproduction steps, and an impact assessment. Screenshots or logs are helpful.
Do not include secrets, customer data, or destructive payloads unless strictly necessary to demonstrate the issue.
In scope: Enji-operated services and infrastructure, such as our website, API, and GitHub App. Out of scope: customer-owned targets, third-party AI providers, and any testing prohibited below.
Safe-harbor expectations
When investigating, please do not:
- Access, modify, delete, or exfiltrate other users’ data.
- Run denial-of-service or load testing.
- Use credential stuffing, phishing, or social engineering.
- Install malware or attempt to maintain persistence.
- Scan unrelated infrastructure.
- Publicly disclose the issue before we have had a chance to respond.
Response
We make a best-effort attempt to acknowledge reports and investigate validated security issues. No bounty, reward, or payment is promised unless a separate written program is published.
Enji Guard