Security Research · Disclosure Policy

AIPWN / SECURITY DIRECTIVES

Vulnerability Disclosure Protocol

AIPwn conducts defensive AI security research under a coordinated-disclosure-first standard.

  1. Authorized and public attack surfaces

    We assess systems we own, environments we are authorized to test, and publicly exposed endpoints using minimal-impact techniques.

  2. Impact minimization

    We prohibit persistence, service disruption, and collection of private data beyond the minimum evidence needed to validate a vulnerability.

  3. Sensitive data redaction

    Tokens, private data, and weaponized payloads are withheld or redacted from public advisories.

  4. Coordinated remediation

    We notify affected maintainers before publication and align timelines with severity, mitigation readiness, and public safety.