Coordinated vulnerability disclosure
How to report a security vulnerability in ProsGrow Serving.
We welcome reports of security vulnerabilities in ProsGrow Serving. This page describes how to report one and what to expect.
Version 2026-08-02 (effective: not yet in effect).
How to report
Email with a description, reproduction steps, and the affected endpoint or host. This mailbox and its machine-readable pointer are published at /.well-known/security.txt (RFC 9116).
Scope
- api.prosgrow.ai — the inference API surface
- console.prosgrow.ai — the customer console
Please do not run automated scanners that degrade availability, attempt denial-of-service, or access another tenant's data. Use only your own account and API keys.
Safe harbor & response commitments — DRAFT, pending legal sign-off.
A binding safe-harbor statement (we will not pursue good-faith research that
follows this policy) and the triage / acknowledgement / fix timelines are legal
and business commitments and are not yet finalized.
What to expect (target, once finalized)
- An acknowledgement that we received your report.
- A coordinated-disclosure timeline agreed with you before any public write-up.
We do not currently run a paid bug-bounty program.