Skip to main content

Security · CVD

Coordinated Vulnerability Disclosure

Last updated: 26 July 2026

Security is the foundation of our product. We run sovereign, on-premise AI systems for enterprises, and we treat reported vulnerabilities with corresponding seriousness. This policy explains how to responsibly report a security issue to us and what you can expect in return.

1. Scope

This policy applies to:

  • the website ai-z-group.com and its associated services,
  • the BRANE appliance (“AI in the Box”) and its management infrastructure,
  • AI-Z-operated endpoints that you can lawfully reach.

Our customers’ systems and data are out of scope: test only against your own systems or against test environments we provide.

2. How to report

Send your report to security@ai-z-group.com. This contact is also published machine-readably at /.well-known/security.txt(RFC 9116).

A helpful report includes:

  • a description of the vulnerability and its potential impact,
  • the affected component, URL or version,
  • clear steps to reproduce (a proof of concept is welcome),
  • your contact details for follow-up questions.

Please do not include real personal or customer data. If you would like to submit encrypted, let us know in an initial email.

3. Our commitment

  • Acknowledgement within 3 business days.
  • Initial assessment (triage and severity) typically within 10 business days.
  • Ongoing updates through to remediation, and coordinated disclosure on a timeline agreed with you.
  • Actively exploited or especially critical issues are handled with priority and elevated urgency.

The stated timeframes are targets and do not constitute contractual claims against AI-Z GmbH.

4. Safe harbour

For good-faith security research conducted under this policy: we consider your activity authorised, will not pursue legal action against you, and will not report you to authorities, provided you

  • respect the privacy of others and access no more data than needed to demonstrate the issue,
  • do not modify or delete data, or degrade availability,
  • keep findings confidential until coordinated disclosure has taken place,
  • stay within scope (section 1).

Any breach of these conditions forfeits this protection without separate notice.

5. Out of scope

  • Denial-of-service (DoS/DDoS) and volume or load testing,
  • social engineering, phishing of staff, or physical attacks,
  • reports consisting solely of automated scanner output with no demonstrated impact,
  • issues that require privileged access to a customer’s own appliance.

6. Recognition

On request, we are glad to credit you in our acknowledgements after remediation. We do not currently run a paid bug-bounty programme.

7. Controller

AI-Z GmbH
Königstraße 26, 70173 Stuttgart, Germany
Security contact: security@ai-z-group.com

This policy follows RFC 9116 (security.txt) and the EU Cyber Resilience Act requirements for coordinated vulnerability disclosure.

Report a vulnerability

Preferably by email (PoC attachments, PGP available) — or directly via the form. Both routes land in the same, immediately escalated channel.

Report by email

PGP-encrypted submission on request — mention it in an initial email.

or