Vulnerability Disclosure
Effective date: 15 September 2026
We welcome reports of suspected vulnerabilities in Enji Guard and related infrastructure. This page explains how to report and what to expect.
Reporting a vulnerability
If you believe you have found a vulnerability in Enji Guard or related Enji infrastructure, email [email protected]. Please include the affected URL, endpoint, repository, or component, a clear description, reproduction steps, and an impact assessment. Screenshots or logs are helpful.
Do not include secrets, customer data, or destructive payloads unless strictly necessary to demonstrate the issue.
In scope: Enji-operated services and infrastructure, such as our website, API, and GitHub App. Out of scope: customer-owned targets, third-party AI providers, our payment provider Paddle, and any testing prohibited below. Report anything you find in Paddle’s own systems to Paddle.
Safe harbour
If you research in good faith within these rules, we will not pursue you. We will not bring a civil claim, we will not report you to law enforcement, and we will not ask your employer or your hosting provider to act against you, for accessing our systems in the course of finding and reporting a vulnerability to us. If someone else does so on our behalf by mistake, tell us and we will put it right.
This is our commitment and not a promise on behalf of third parties. If your testing reaches infrastructure we do not control, their rules apply and we cannot waive them for you.
What we ask in return. When investigating, please do not:
- Access, modify, delete, or exfiltrate other users’ data.
- Run denial-of-service or load testing.
- Use credential stuffing, phishing, or social engineering.
- Install malware or attempt to maintain persistence.
- Scan unrelated infrastructure.
- Publicly disclose the issue before we have had a chance to respond.
Response
We will acknowledge your report within 5 business days and tell you what we think of it within 30 days, or explain why we need longer. We will let you know when it is fixed.
Disclosure. We ask you to hold off publishing until a fix is out, and we will agree a date with you rather than leaving it open. If we have not fixed it within 90 days and have not agreed a different timetable with you, you are free to publish.
No bounty, reward, or payment is promised unless a separate written program is published.
Your data. To handle a report we process the contact details and the content you send us. We keep them as security records — see Privacy Policy — and we will not publish your name or contact details without asking you first.
Enji Guard