1. Purpose
AIZeryn LLC is committed to protecting the security, privacy, and integrity of its website and information systems. We welcome responsible security research that helps us identify and address vulnerabilities.
This policy explains:
- Which systems are covered;
- What security testing is permitted;
- What activities are prohibited;
- How to report a suspected vulnerability;
- How AIZeryn will review and respond to reports; and
- The protections available to researchers who act in good faith and follow this policy.
This policy applies only to AIZeryn LLC as a company and does not describe or reference any particular product, application, service, feature, or future offering.
2. Scope
The authorized scope includes:
- The public AIZeryn website at https://aizeryn.com;
- AIZeryn-owned web properties and domains expressly identified by AIZeryn;
- Publicly accessible AIZeryn systems that are operated and controlled by AIZeryn LLC; and
- Security vulnerabilities affecting AIZeryn-controlled infrastructure, websites, applications, or services.
A system is not considered in scope merely because it displays AIZeryn branding or is accessible through an AIZeryn website. If you are uncertain whether a system is in scope, contact us before testing.
Third-Party Systems
Third-party systems, hosting environments, cloud services, vendors, and service providers are not automatically included in this policy. Researchers must not test a third party on AIZeryn's behalf without the third party's express authorization.
If a suspected vulnerability appears to involve a third party, report it to AIZeryn without conducting further testing that could affect that third party.
3. Authorized Security Research
AIZeryn authorizes good-faith security research within the scope of this policy, provided that the researcher:
- Limits testing to the minimum activity reasonably necessary to confirm the vulnerability;
- Avoids accessing, copying, modifying, deleting, or disclosing information belonging to other individuals or organizations;
- Does not disrupt or degrade the availability, confidentiality, or integrity of any system;
- Uses test accounts or other accounts owned or authorized by the researcher whenever possible;
- Stops testing promptly if sensitive information, personal information, credentials, or unrelated data is encountered;
- Reports the vulnerability promptly and privately to AIZeryn;
- Does not publicly disclose the vulnerability before coordinating disclosure with AIZeryn; and
- Complies with all applicable laws and this policy.
Researchers may use automated tools only when doing so is reasonably unlikely to affect system availability or performance. AIZeryn may ask a researcher to stop testing or to take other measures to protect systems or information.
4. Prohibited Activities
The following activities are not authorized under this policy:
- Denial-of-service, distributed denial-of-service, stress, load, or availability testing;
- Any activity intended to degrade, interrupt, or disable a system;
- Accessing, exfiltrating, downloading, retaining, selling, or disclosing personal information or confidential information;
- Modifying, deleting, encrypting, corrupting, or destroying data;
- Establishing persistence, creating backdoors, or maintaining unauthorized access;
- Pivoting from an AIZeryn system to another system or network;
- Brute-force attacks against accounts, passwords, tokens, or authentication systems;
- Credential stuffing, password spraying, or testing credentials that do not belong to the researcher;
- Social engineering, phishing, pretexting, impersonation, or targeting AIZeryn personnel, customers, users, vendors, or other individuals;
- Physical security testing, including unauthorized access to offices, facilities, equipment, or restricted areas;
- Introducing malware, ransomware, destructive code, or other harmful content;
- Testing systems owned or operated by third parties without their express authorization;
- Sending spam or excessive volumes of requests or messages;
- Using a vulnerability to obtain compensation, extort AIZeryn, or threaten disclosure;
- Publicly disclosing a vulnerability or publishing proof-of-concept materials before coordinated disclosure;
- Accessing accounts, records, or data that do not belong to the researcher;
- Testing in a manner that violates another person's privacy or applicable law; or
- Any activity that exceeds the minimum testing reasonably necessary to verify a suspected vulnerability.
If testing unintentionally causes disruption or exposes sensitive information, stop immediately and notify AIZeryn.
5. Reporting a Vulnerability
Please report suspected vulnerabilities as soon as reasonably practicable after discovery.
Reports may be submitted to:
- Security email: info@aizeryn.com
- Privacy and legal contact: privacy@aizeryn.com
If the security email is unavailable, a report may be submitted through the contact method listed on the AIZeryn website. Do not include sensitive information in an ordinary, unencrypted contact-form submission unless AIZeryn specifically instructs you to do so.
Researchers may submit reports anonymously. However, providing contact information allows AIZeryn to ask follow-up questions, provide status updates, and coordinate remediation.
6. Information to Include
To help us evaluate and address a report, please include, where available:
- A clear description of the suspected vulnerability;
- The affected website, domain, endpoint, system, or component;
- The type and potential impact of the vulnerability;
- Detailed steps to reproduce the issue;
- Proof-of-concept code, screenshots, logs, or other evidence, if safe and necessary;
- The date and approximate time of testing;
- The tools or techniques used;
- Any accounts or test data used;
- The minimum access obtained or attempted;
- Suggested remediation or mitigation steps;
- Whether any personal, confidential, or sensitive information was encountered; and
- A preferred method of contact.
Please redact personal information, credentials, authentication tokens, and other sensitive information before submitting a report whenever possible.
7. Handling Sensitive Information
Researchers must not intentionally access or retain personal information, confidential information, authentication credentials, or other data unrelated to confirming a vulnerability.
If such information is encountered accidentally:
- Stop testing immediately;
- Do not copy, download, share, or further access the information;
- Notify AIZeryn promptly;
- Identify only the minimum information necessary to help AIZeryn locate and secure the issue; and
- Securely delete any information obtained unintentionally when AIZeryn confirms that it is no longer needed.
AIZeryn may provide additional instructions for securely transferring or destroying information.
8. AIZeryn's Response Process
AIZeryn generally follows this process:
- Acknowledgment: We will attempt to acknowledge receipt within three business days.
- Triage: We will assess whether the report is in scope, reproducible, and relevant to AIZeryn systems.
- Validation: We may contact the researcher for additional information or limited confirmation testing.
- Risk assessment: We will evaluate the severity, exploitability, affected systems, and potential impact.
- Remediation: We will coordinate appropriate mitigation, correction, monitoring, or other protective measures.
- Verification: Where appropriate, we may ask the researcher to verify that the issue has been addressed.
- Closure or disclosure: We will communicate the status of the report where reasonably practicable and coordinate any public disclosure when appropriate.
Response times may vary based on the complexity, severity, business impact, availability of affected systems, and involvement of third parties. AIZeryn does not guarantee a particular remediation period or outcome.
AIZeryn may combine duplicate reports, classify a report as informational or out of scope, or determine that no action is required. We may also decline to provide details about internal security controls, investigations, remediation, or other confidential matters.
9. Coordinated Disclosure
Researchers must not publicly disclose a suspected vulnerability, vulnerability details, exploit code, screenshots containing sensitive information, or other proof-of-concept material without prior written coordination with AIZeryn.
AIZeryn will work in good faith with researchers to determine whether, when, and how disclosure should occur. Any disclosure timeline should account for remediation, user protection, third-party coordination, and the risk of continued exploitation.
Unless otherwise agreed in writing, researchers should allow AIZeryn at least 90 days after receiving a sufficiently detailed report before considering public disclosure. AIZeryn may request a reasonable extension when remediation requires additional time.
If immediate public disclosure is necessary because active exploitation or substantial public risk exists, the researcher should contact AIZeryn before disclosure whenever practicable.
10. Safe Harbor for Good-Faith Research
AIZeryn will not initiate or recommend legal action against a researcher for security research that:
- Is conducted in good faith;
- Is limited to systems within the scope of this policy;
- Complies with the testing requirements and restrictions in this policy;
- Avoids accessing, retaining, modifying, or disclosing data unnecessarily; and
- Is promptly reported to AIZeryn and kept confidential while remediation is pursued.
This safe harbor is intended to encourage responsible security research and applies only to AIZeryn's rights and potential actions. It does not:
- Authorize conduct outside the scope of this policy;
- Protect conduct that violates applicable law;
- Protect testing of third-party systems without authorization;
- Prevent AIZeryn from responding to an actual or threatened security incident;
- Prevent AIZeryn from complying with legal obligations;
- Waive rights or remedies belonging to third parties;
- Protect intentional, malicious, reckless, fraudulent, extortionate, or harmful conduct; or
- Guarantee immunity from civil, criminal, regulatory, or other action by another person, organization, or government authority.
If a researcher has concerns about whether proposed testing is covered, the researcher should contact AIZeryn before beginning or continuing the activity.
11. Compensation and Recognition
AIZeryn does not currently operate a paid bug bounty program and does not promise compensation, rewards, employment, or other consideration for vulnerability reports.
AIZeryn may recognize researchers publicly, with their permission, after a vulnerability has been addressed. Researchers should not publicly claim an endorsement, partnership, or affiliation with AIZeryn without prior written permission.
12. Privacy
Personal information submitted in connection with a vulnerability report will be used to evaluate, communicate about, and remediate the reported issue, protect AIZeryn systems, and comply with legal obligations.
AIZeryn will handle personal information in accordance with its Privacy Policy. Researchers should submit only information reasonably necessary to investigate the vulnerability.
13. Changes to This Policy
AIZeryn may update this policy from time to time to reflect changes in its systems, security practices, legal obligations, or vulnerability-response process.
The Last Updated date at the beginning of this policy indicates when the current version took effect. Researchers should review the current version before conducting testing.
14. Contact
For questions about this policy or to report a suspected vulnerability, contact:
AIZeryn LLC
Registered/mailing address: AIZeryn LLC, 5668 Fishhawk Crossing Blvd, Suite 363, Lithia, FL 33547
Tampa, Florida
Security: info@aizeryn.com
Privacy and legal inquiries: privacy@aizeryn.com
When reporting a suspected vulnerability, please use the subject line:
Responsible Disclosure — [Brief Vulnerability Description]