Security
Reporting a security issue to SymGraph
SymGraph accepts good-faith reports about security issues discovered during normal, authorized use of the service. This is not a bug bounty program and does not invite dedicated security testing, scanning, or probing of our systems.
Not a bug bounty
No rewards or recognition program
SymGraph does not offer monetary rewards, compensation, swag, public credit, or other recognition for reports. Our former reporter recognition program has been discontinued. Submitting a report does not create any entitlement to a response, reward, credit, or public acknowledgment.
Reporting
Send a complete report to security@symgraph.ai
Use our public PGP key if encrypted communication is necessary. Send one complete, technically validated report with enough detail for independent reproduction.
Submission and communication policy
Due to the volume of low-quality and automated submissions, SymGraph does not acknowledge receipt of security reports. We do not provide triage decisions, report status, remediation plans, mitigation updates, disclosure coordination, or confirmation that an issue has been fixed. Reports may be reviewed and acted upon internally without further communication. Please do not send repeated reports or follow-up requests for status.
Reports we accept
- A reproducible vulnerability affecting a SymGraph-operated production service.
- A concrete security impact, realistic attack scenario, and affected account or data boundary.
- An issue you encountered in good faith during ordinary, authorized use of the service.
- Enough technical detail for our team to reproduce and assess the issue independently.
What to include
- Affected SymGraph URL, endpoint, or feature
- Clear reproduction steps and required prerequisites
- Demonstrated security impact and realistic attack scenario
- Minimal proof-of-concept, logs, screenshots, or code needed to reproduce the issue
- Confirmation that the issue was found during normal authorized use and that no third-party data was accessed
Out of scope
- Automated, scanner-only, templated, speculative, or unverified reports.
- Dedicated probing, scanning, fuzzing, brute-force testing, denial-of-service testing, or other activity beyond normal use.
- Missing headers, version banners, configuration preferences, or best-practice observations without a demonstrated security impact.
- Social engineering, phishing, pretexting, physical attacks, spam, or attacks against staff, users, vendors, or infrastructure.
- Accessing, downloading, retaining, modifying, or sharing another user’s or organization’s data.
- Third-party services, customer-managed deployments, or systems not owned and operated by SymGraph.
No authorization to test
This policy is a channel for reporting issues encountered during normal use. It does not grant authorization to test, scan, probe, exploit, disrupt, or access SymGraph systems, accounts, or data. Use only accounts and data you are authorized to access. If you encounter another party’s data unintentionally, stop immediately, do not retain or share it, and include only the minimum information needed to report the exposure.
Privacy and report handling
Do not include personal information, credentials, secrets, or third-party data that is not strictly necessary to describe the issue. Report content and sender details may be retained and used for security operations, incident response, legal compliance, and abuse prevention.