Report a Security Issue

Report security vulnerabilities in Curiosity Workspace, the Curiosity website, or any other Curiosity-operated service to security@curiosity.ai.

Where to send it

Email security@curiosity.ai. If the report contains sensitive material, ask for our PGP key in a first message and we will send you the current one.

We do not currently operate a paid bug-bounty program. With the reporter's consent we credit contributions by name in the advisory and in the release notes.

What to include

An actionable report contains:

  • The affected product, URL, or component, and the build number or commit you tested against. For a workspace, the build number is shown in the admin area under Configure → Workspace → About.
  • A description of the vulnerability and the impact you believe it has.
  • Step-by-step reproduction instructions — proof-of-concept code, raw HTTP requests, screenshots, or a short video.
  • Any logs, request IDs, or timestamps that help us correlate the issue on our side.
  • Your name or handle, if you would like to be credited.

What to expect

We acknowledge every report within two business days, give you an initial triage assessment within five business days, and update you at least every two weeks until the issue is closed.

The security team will:

  1. Confirm receipt of your report.
  2. Triage and reproduce the issue against the affected build.
  3. Assign a severity using CVSS v4.0.
  4. Coordinate remediation with the engineering team that owns the affected component.
  5. Publish a security advisory once a fixed build is available, if the issue reached a released build and requires customer action.
  6. Notify you when the fix ships, and credit you in the advisory and release notes where appropriate.

Testing rules

When researching potential issues, you must:

  • Avoid privacy violations and service disruption. Do not access, modify, or destroy data that does not belong to you. Do not run denial-of-service attacks, automated load testing, or large-scale brute force against our systems.
  • Use your own workspace. Curiosity Workspace can be self-hosted, which is the best way to test it — you get an environment you fully control. Do not interact with other customers' workspaces.
  • Stop and report. As soon as you confirm an issue, stop testing and report it. Do not pivot, exfiltrate data, or maintain access.
  • Keep findings confidential until we have confirmed a fix is deployed or 90 days have passed since the initial report — whichever is sooner. We are happy to coordinate a public disclosure timeline with you.

We will not pursue legal action against researchers who act in good faith and follow these rules.

Out of scope

The following are generally not treated as security vulnerabilities:

  • Reports generated solely by automated scanners without a working proof of concept.
  • Missing security headers, cookie flags, or TLS configuration grades that do not lead to a concrete vulnerability.
  • Issues that require a compromised user device, an attacker already holding the victim's credentials, or social engineering against Curiosity staff.
  • Rate-limiting on non-sensitive endpoints.
  • Self-XSS, clickjacking on pages with no sensitive actions, or open redirects without demonstrable impact.
  • Behaviour that a workspace administrator configured deliberately — for example an endpoint published with an access mode of Unrestricted. See Access control model.
  • Vulnerabilities in third-party services we do not operate. Report those upstream.
  • Best-practice or hardening recommendations without a concrete attack path. We welcome these as feedback, but they are not vulnerabilities.

If you are unsure whether something is in scope, send it anyway.

© 2026 Curiosity. All rights reserved.
Powered by Neko