Security · CVD
Coordinated Vulnerability Disclosure
Last updated: 26 July 2026
Security is the foundation of our product. We run sovereign, on-premise AI systems for enterprises, and we treat reported vulnerabilities with corresponding seriousness. This policy explains how to responsibly report a security issue to us and what you can expect in return.
1. Scope
This policy applies to:
- the website
ai-z-group.comand its associated services, - the BRANE appliance (“AI in the Box”) and its management infrastructure,
- AI-Z-operated endpoints that you can lawfully reach.
Our customers’ systems and data are out of scope: test only against your own systems or against test environments we provide.
2. How to report
Send your report to security@ai-z-group.com. This contact is also published machine-readably at /.well-known/security.txt(RFC 9116).
A helpful report includes:
- a description of the vulnerability and its potential impact,
- the affected component, URL or version,
- clear steps to reproduce (a proof of concept is welcome),
- your contact details for follow-up questions.
Please do not include real personal or customer data. If you would like to submit encrypted, let us know in an initial email.
3. Our commitment
- Acknowledgement within 3 business days.
- Initial assessment (triage and severity) typically within 10 business days.
- Ongoing updates through to remediation, and coordinated disclosure on a timeline agreed with you.
- Actively exploited or especially critical issues are handled with priority and elevated urgency.
The stated timeframes are targets and do not constitute contractual claims against AI-Z GmbH.
4. Safe harbour
For good-faith security research conducted under this policy: we consider your activity authorised, will not pursue legal action against you, and will not report you to authorities, provided you
- respect the privacy of others and access no more data than needed to demonstrate the issue,
- do not modify or delete data, or degrade availability,
- keep findings confidential until coordinated disclosure has taken place,
- stay within scope (section 1).
Any breach of these conditions forfeits this protection without separate notice.
5. Out of scope
- Denial-of-service (DoS/DDoS) and volume or load testing,
- social engineering, phishing of staff, or physical attacks,
- reports consisting solely of automated scanner output with no demonstrated impact,
- issues that require privileged access to a customer’s own appliance.
6. Recognition
On request, we are glad to credit you in our acknowledgements after remediation. We do not currently run a paid bug-bounty programme.
7. Controller
AI-Z GmbH
Königstraße 26, 70173 Stuttgart, Germany
Security contact: security@ai-z-group.com
This policy follows RFC 9116 (security.txt) and the EU Cyber Resilience Act requirements for coordinated vulnerability disclosure.
Report a vulnerability
Preferably by email (PoC attachments, PGP available) — or directly via the form. Both routes land in the same, immediately escalated channel.
PGP-encrypted submission on request — mention it in an initial email.