EastStar AI
Security
Private vulnerability reporting guidance for EastStar AI and Sanad.
Effective on production publication
Report privately
Use the approved WhatsApp contact to begin a private report. Do not post an unpatched vulnerability publicly or send live credentials, private keys, tokens, or unrelated personal data. We may coordinate a safer channel for technical evidence.
What to include
Include the affected component and version, impact, reproducible steps, and suggested mitigation. Test only systems you own or are authorized to assess. Avoid privacy violations, disruption, data destruction, and persistence.
Response boundary
We will acknowledge a complete report when operationally possible and coordinate based on severity. No bug bounty or response-time promise is offered unless announced separately.