Security
Responsible Disclosure
How to report a security vulnerability to Chameleon Eye AI.
How to Report
Submit security reports via the contact form. Chameleon Eye takes all reports seriously.
Report Security Issues
Submit security vulnerability reports via the contact form with the subject line "Security Report". A dedicated security contact email will be published following commercial launch.
Include in your report: a clear description of the vulnerability, steps to reproduce it, the potential impact, and any proof-of-concept code or screenshots if relevant.
Disclosure Rules
- +Report suspected vulnerabilities responsibly.
- +Do not access other users' data.
- +Do not run destructive tests.
- +Do not perform denial-of-service testing.
- +Provide clear reproduction steps.
- +The company will review valid reports responsibly.
Response Timeline
Public Bug Bounty
A public bug bounty programme is not currently active. Chameleon Eye appreciates responsible security researchers and will recognise researchers who report valid, high-impact vulnerabilities responsibly.
What to Report
- +Authentication bypass or account takeover
- +Data exposure or unauthorised data access
- +SQL injection or command injection vulnerabilities
- +Broken access controls
- +Sensitive data leaks (PII, credentials, tokens)
- +API key exposure in frontend or public endpoints
- +Cross-site scripting (XSS) with significant impact
- +Server-side request forgery (SSRF)
Safe Harbour
Acting within these guidelines constitutes good-faith security research.
Acting within the guidelines above constitutes good-faith security research. Chameleon Eye will not pursue legal action against researchers who follow these guidelines. Actions outside these guidelines may result in legal action under applicable computer fraud and cybercrime laws.
