Legal

Responsible Disclosure / Vulnerability Disclosure Policy

Effective Date: August 2026

AI312TEC is committed to maintaining the highest standards of cybersecurity, protecting our customers, partners, employees, and digital infrastructure against evolving cyber threats.

We recognize that security researchers, ethical hackers, customers, and members of the cybersecurity community play an important role in identifying potential vulnerabilities before they can be exploited by malicious actors.

This Responsible Disclosure Policy explains how security vulnerabilities affecting AI312TEC systems should be reported and how we will respond to responsible security research conducted in good faith.

1.Purpose

The purpose of this Policy is to establish a secure, transparent, and collaborative process for reporting security vulnerabilities while protecting both AI312TEC and individuals acting responsibly to improve cybersecurity.

Our objective is to:

  • Improve the security of our services.
  • Encourage responsible vulnerability reporting.
  • Protect customers and partners.
  • Minimize cybersecurity risks.
  • Promote ethical security research.
  • Resolve security issues efficiently.

2.Scope

This Policy applies to vulnerabilities discovered within:

  • AI312TEC public websites
  • Customer portals
  • Web applications
  • APIs
  • Cloud-hosted services
  • Online platforms
  • Public-facing infrastructure
  • Digital services owned and operated by AI312TEC

Unless explicitly authorized in writing, this Policy does not apply to third-party systems, products, or services that are not owned or managed by AI312TEC.

3.Good Faith Security Research

AI312TEC welcomes vulnerability reports submitted in good faith.

Security research is considered to be conducted in good faith when the researcher:

  • Acts with the intention of improving security.
  • Avoids causing harm to systems or users.
  • Protects customer privacy.
  • Does not access, modify, or destroy data unnecessarily.
  • Reports vulnerabilities privately.
  • Allows AI312TEC reasonable time to investigate and remediate issues before any public disclosure.
  • Cooperates with our security team throughout the remediation process.

4.What to Report

We encourage reports involving potential security issues such as:

  • Authentication bypass
  • Authorization vulnerabilities
  • Privilege escalation
  • Remote Code Execution (RCE)
  • SQL Injection
  • Command Injection
  • Cross-Site Scripting (XSS)
  • Cross-Site Request Forgery (CSRF)
  • Server-Side Request Forgery (SSRF)
  • Insecure Direct Object References (IDOR)
  • Security misconfigurations
  • Information disclosure
  • Sensitive data exposure
  • Business logic flaws
  • Cloud security weaknesses
  • API security vulnerabilities
  • Identity and access control issues
  • Cryptographic weaknesses
  • Session management vulnerabilities

5.Out of Scope

The following are generally considered out of scope unless they present a significant security impact:

  • Social engineering attacks.
  • Physical security issues.
  • Denial of Service (DoS/DDoS) testing.
  • Spam reports.
  • Missing HTTP security headers without exploitable impact.
  • Self-XSS.
  • Clickjacking on non-sensitive pages.
  • Rate limiting issues without demonstrated abuse.
  • Weak password policies where Multi-Factor Authentication is enforced.
  • Vulnerabilities affecting third-party providers.
  • Best practice recommendations without a demonstrable security risk.

6.Responsible Research Guidelines

Researchers are expected to:

  • Respect user privacy.
  • Avoid service disruption.
  • Avoid automated high-volume scanning.
  • Use the minimum amount of testing required.
  • Never intentionally access customer data.
  • Never alter data.
  • Never destroy information.
  • Never install malware.
  • Never create persistence mechanisms.
  • Never exploit vulnerabilities beyond what is necessary to demonstrate their existence.
  • Stop testing immediately if customer data is exposed.

7.How to Report a Vulnerability

When reporting a vulnerability, please include as much information as possible, including:

  • Description of the vulnerability.
  • Affected URL or system.
  • Steps required to reproduce the issue.
  • Technical details.
  • Screenshots where appropriate.
  • Proof of Concept (PoC), if available.
  • Potential security impact.
  • Suggested remediation, if applicable.

Reports should be submitted to:

8.Security Team

Email: security@ai312tec.com

Website: www.ai312tec.com

9.Our Commitment

Upon receiving a vulnerability report, AI312TEC will:

  • Acknowledge receipt of the report.
  • Review the submitted information.
  • Validate the reported issue.
  • Assess the security impact.
  • Prioritize remediation according to risk.
  • Keep the reporter informed throughout the investigation process where appropriate.
  • Resolve confirmed vulnerabilities as quickly as reasonably possible.

10.Coordinated Vulnerability Disclosure

AI312TEC supports Coordinated Vulnerability Disclosure (CVD).

We kindly request that researchers do not publicly disclose vulnerabilities until:

  • AI312TEC has completed its investigation.
  • Appropriate remediation has been implemented.
  • Customers have been adequately protected.
  • A mutually agreed disclosure timeline has been reached.

Responsible disclosure helps reduce unnecessary risk to customers and the broader cybersecurity community.

11.Safe Harbor

AI312TEC considers security research conducted in accordance with this Policy to be authorized.

We will not initiate legal action against researchers acting:

  • In good faith.
  • Within the scope of this Policy.
  • Without malicious intent.
  • Without violating applicable laws.
  • Without compromising customer privacy.

This Safe Harbor statement does not provide immunity for activities that exceed the scope of this Policy or violate applicable laws.

12.Confidentiality

All submitted vulnerability reports will be handled confidentially.

AI312TEC will not publicly disclose the identity of researchers without their prior consent unless required by law.

Likewise, researchers are expected to maintain confidentiality regarding discovered vulnerabilities until coordinated disclosure has been completed.

13.Recognition

AI312TEC values contributions from the cybersecurity community.

Where appropriate, and subject to the researcher's consent, we may acknowledge responsible security researchers who have contributed to improving the security of our systems.

Recognition does not imply financial compensation unless explicitly stated in a separate agreement.

14.Exclusions

This Policy does not authorize:

  • Unauthorized penetration testing.
  • Exploitation of customer systems.
  • Data theft.
  • Data modification.
  • Installation of malicious software.
  • Social engineering attacks.
  • Physical attacks.
  • Service disruption.
  • Extortion.
  • Blackmail.
  • Demands for payment in exchange for withholding vulnerability disclosure.

Such activities may be investigated and referred to the appropriate authorities.

15.Changes to this Policy

AI312TEC reserves the right to modify this Responsible Disclosure Policy at any time.

The most current version will always be published on our website together with its effective date.

Continued use of our services constitutes acceptance of any updated version of this Policy.

16.Governing Law

This Responsible Disclosure Policy shall be governed by the laws of the Hellenic Republic and applicable European Union legislation.

Any disputes arising under this Policy shall be subject to the exclusive jurisdiction of the competent courts of Greece.

17.Contact Information

For security-related inquiries or to report a vulnerability, please contact:

AI312TEC

18.Security Response Team (SRT)

Email: info@ai312tec.com

Website: www.ai312tec.com