Vulnerability Disclosure Policy
Last updated: July 14, 2026
Vight welcomes reports from security researchers and customers who believe they have found a vulnerability in our products or infrastructure. This page explains how to report an issue and what you can expect from us.
How to Report
Email security@vight.ai with as much of the following as you can:
- A description of the vulnerability and its potential impact
- Steps to reproduce it, including any URLs, requests, or sample payloads
- The account or environment you used while testing
- How we can reach you for follow-up questions
Scope
This policy covers:
- vight.ai and app.vight.ai, including our APIs
- The Vight apps for Slack and Microsoft Teams
What We Commit To
- We will acknowledge your report within 3 business days
- We will investigate, keep you informed of our progress, and tell you when the issue is fixed
- We will not pursue legal action against researchers who follow this policy and act in good faith
We do not currently offer paid rewards for vulnerability reports.
Guidelines for Researchers
To stay within this policy:
- Only test against accounts and data you own or are authorized to use
- Do not access, modify, or delete another customer's data; if you encounter it accidentally, stop and report it immediately
- Do not run denial-of-service tests or automated scanning that degrades the service
- Do not use social engineering, phishing, or physical attacks against Vight staff or customers
- Give us a reasonable amount of time to fix the issue before disclosing it publicly