Legal
Security
Last updated:
If you believe you have found a security vulnerability in Elysium, please tell us. We welcome reports from security researchers and will work with you to fix what you find.
How to report
Email security@elysium-labs.ai. Please include what you found and where (the address or component), how to reproduce it, what an attacker could do with it, and how we can reach you. Leave out other people's personal data beyond what is needed to show the problem. We read reports in English.
What we do
- We confirm that we received your report within 5 business days.
- We keep you informed while we work on a fix, and tell you when it is fixed.
- If you would like, we thank you by name when we publish the fix. We do not pay for reports.
Scope
You may test:
- elysium-labs.ai
- dev.elysium-labs.ai, including our API under /api and /socket.io
- dashboard.dev.elysium-labs.ai (the Elysium app)
- The Elysium software on a hub you own
These are out of scope:
- denial of service and load testing;
- social engineering, phishing, or physical attacks on people or premises;
- mass submissions to forms that send email, such as the early-access form, which sends real email to real people: use only addresses you own;
- services run by others, such as Amazon Web Services, Google, Anthropic, OpenAI and ImprovMX: please report to them;
- reports from automated scanners, and missing headers or best practices, without a demonstrated security impact.
Testing in good faith
- Test only with accounts and households that are yours, or that you have permission to use. Early access is by invitation: if you need a test account, ask us at security@elysium-labs.ai.
- Stop as soon as you reach data that is not yours. Do not keep or share it, and tell us what you saw.
- Do not change or delete data that is not yours, and do not degrade the service for others.
- Do no more than you need to show the problem.
- Keep the details confidential until we have fixed the problem, or for 90 days after your report if that comes first. If a fix needs longer, we will agree a date with you.
Safe harbor
If you act in good faith and follow this policy:
- we consider your research authorized, and we will not take legal action against you or report you to the police for it;
- the rule in our Terms of Service against probing or testing the service does not apply to it;
- if someone else takes legal action against you for research that followed this policy, we will make it known that we authorized it.
We can authorize testing only of systems we control. If you are unsure whether something is allowed, ask us first at security@elysium-labs.ai. This policy is also published in machine-readable form at /.well-known/security.txt.