Skip to content

Route5

Trust · VDP

Report it. We’ll take it seriously.

Responsible disclosure policy for Route5. No fake bug-bounty theater — clear intake, clear response targets, clear scope.

Full Trust Center copy follows this language.
Ack ≤ 2 business daysLanguages: follows your localeIncident response →

How disclosure works

  • Report

    Email neville@route5ai.com with steps to reproduce, impact, and any PoC. Prefer clear write-ups over noisy scanners.

  • Acknowledge

    We aim to acknowledge within 2 business days. You will get a tracking note — not silence.

  • Triage

    We classify severity, confirm reproducibility, and scope blast radius. Legal hold / customer notify rules apply when required.

  • Fix & credit

    We patch, verify, and may credit you on acknowledgments if you want. No bounty program yet — honesty over theater.

In scope

  • route5ai.com and authenticated product surfaces
  • Authentication / session handling, authorization gaps, injection, SSRF, RCE
  • Sensitive data exposure in APIs or exports
  • Desktop Electron shell sandbox escapes (when applicable)

Out of scope

  • Social engineering of Route5 staff or customers
  • DoS / volumetric floods without prior coordination
  • Reports from automated scanners with no validated impact
  • Issues in third-party IdPs / Stripe / Clerk themselves (report upstream)

Safe harbor

If you research in good faith, avoid privacy violations and service disruption, and report promptly, we will not pursue legal action for that research. Do not access other customers’ data. If you accidentally do — stop and tell us immediately.