Security

Vulnerability Disclosure Policy

Last updated: May 14, 2026

Detectabli takes the security of its systems seriously and welcomes reports from individuals who identify potential security vulnerabilities affecting our platform. This Policy explains how to report a suspected vulnerability, what we ask you to include, what you can expect from us in return, and the safe harbor we extend to researchers who follow it. Detectabli is a trade name of Unlocked AEO Inc., an Ontario corporation based in Toronto, Canada.

01

How to Report

Please send reports to contact@detectabli.com with the subject line SECURITY DISCLOSURE.

At a minimum, please include: a description of the suspected vulnerability and its potential impact; steps to reproduce the issue; and your contact information.

If available, please also include supporting materials that help us validate the issue, such as screenshots, request and response samples, affected URLs or endpoints, IP addresses, logs, proof-of-concept code, or suggested remediation.

Acknowledgement: Detectabli aims to acknowledge initial reports within five (5) business days and to provide a substantive response or status update within fifteen (15) business days. Complex issues may take longer to investigate, in which case we will keep you informed.

We prefer plain-text or PDF submissions. If your report contains sensitive technical detail you would like to encrypt, ask us in your first email and we will provide a PGP key.

02

Scope

This Policy applies to suspected vulnerabilities affecting assets that Detectabli owns or operates, including: the Detectabli web application and any subdomain of detectabli.com; the Detectabli public API and any documented endpoints; the Detectabli Model Context Protocol (MCP) server and any tools exposed through it; the Detectabli authentication and account infrastructure; and any official Detectabli mobile or desktop client, if and when published.

Reports relating solely to third-party products, services, or infrastructure not controlled by Detectabli are outside the scope of this Policy, unless the report demonstrates that the issue is caused by Detectabli's own code, configuration, or implementation.

03

Out of Scope

The following are outside the scope of this Policy and are not eligible for safe harbor under Section 6:

Social engineering, phishing, or impersonation of Detectabli personnel, customers, or vendors. Physical security issues, including attacks against Detectabli offices or staff. Denial-of-service (DoS) or distributed denial-of-service (DDoS) activity, volumetric attacks, brute force, or credential stuffing. Malware, ransomware, or destructive payloads of any kind. Spam, abuse, or content-policy reports. Issues involving third-party services, AI Platforms, or infrastructure that Detectabli does not own or control. Theoretical findings without a demonstrable security impact, or reports lacking sufficient detail for us to reproduce the issue. Best-practice or hardening recommendations that do not represent an exploitable vulnerability (e.g. missing security headers without a working attack chain). Findings already reported by another researcher.

04

Researcher Expectations

When identifying and reporting a suspected vulnerability, we ask that you:

Act in good faith and use only the access necessary to demonstrate the issue. Provide accurate and complete information. Do not access, use, modify, exfiltrate, disclose, or delete any data that does not belong to you — if you inadvertently access another customer's data, stop immediately, do not save or share it, and include the incident in your report. Avoid any activity that disrupts, degrades, or impairs Detectabli services or the experience of other users (no DoS, no automated volumetric testing, no destructive proofs-of-concept). Use test accounts you create yourself rather than accessing real customer accounts. Report the issue privately to Detectabli and give us a reasonable opportunity to investigate and remediate before any public disclosure (see Section 7).

05

Bug Bounty

Detectabli does not currently operate a paid bug bounty program. We may, at our sole discretion, recognise individual researchers in a public acknowledgements page or by other means. Any decision whether to offer recognition or any other form of acknowledgement, and the form it takes, is solely up to Detectabli.

If we introduce a paid bug bounty program in the future, the terms will be published separately and will apply prospectively.

06

Safe Harbor

If you make a good-faith effort to comply with this Policy while identifying and reporting a suspected security vulnerability, Detectabli will: not initiate or support legal action against you under Section 342.1 of the Criminal Code (Canada), the U.S. Computer Fraud and Abuse Act (CFAA), the U.S. Digital Millennium Copyright Act (DMCA), or any analogous federal, provincial, state, or foreign law, based solely on your participation in this process; consider your activity to be authorized for the purposes of those laws; and work in good faith with you to understand and resolve the issue.

This safe harbor applies only if your activities: are limited to assets expressly identified as in scope under Section 2; comply with the restrictions and expectations set out in Sections 3 and 4; do not involve accessing, using, modifying, disclosing, or deleting data that does not belong to you; do not disrupt, degrade, or impair Detectabli systems, services, or third-party services; and are reported promptly and privately to Detectabli at contact@detectabli.com.

This safe harbor does not apply to conduct that falls outside the scope of this Policy, causes harm to Detectabli, our customers, or any third party, involves third-party systems or data, or otherwise violates applicable law. Detectabli reserves all rights with respect to any conduct outside the scope of this Policy.

If you are uncertain whether a specific action is authorized, contact us at contact@detectabli.com first.

07

Coordinated Disclosure

We ask that you do not publicly disclose a suspected vulnerability until Detectabli has had a reasonable opportunity to investigate and remediate the issue. Our standard coordinated-disclosure window is ninety (90) days from the date we acknowledge your report, after which you are free to disclose publicly, subject to the safe-harbor conditions above.

If a fix is straightforward we will often release it sooner, and we will keep you informed throughout. If a vulnerability is genuinely complex and we need additional time, we will explain why and propose a revised timeline. We will not unreasonably extend the disclosure window to delay public disclosure.

If you intend to publish a write-up, we ask that you share a draft with us in advance so we can confirm the technical detail and the affected versions, and (with your agreement) credit you in any advisory we publish.

08

Reservation of Rights

Detectabli reserves the right to determine, in its sole discretion: whether a reported issue constitutes a security vulnerability; whether a report is within the scope of this Policy; what actions, if any, Detectabli will take in response; and whether any recognition will be offered.

This Policy may be updated from time to time. The Last updated date at the top of this page reflects the current version.

09

Contact

Send all reports and questions about this Policy to contact@detectabli.com with the subject line SECURITY DISCLOSURE. Thank you for helping keep Detectabli and our customers safe.

Unlocked AEO Inc. (trading as Detectabli)Toronto, Ontario, Canada