Skip to content
BestAIToolix

Security & Vulnerability Reporting

Effective 2026-09-13

Reporting a vulnerability

Email security@bestaitoolix.com with details and reproduction steps. We acknowledge reports within 3 business days. Please do not test against production user accounts, and give us a reasonable window to fix before public disclosure.

What we ask

  • Test only with accounts you own.
  • No automated scanning at disruptive volumes, no denial-of-service testing.
  • Data you accidentally gain access to: report it, don't exfiltrate it.

Our commitments

  • Security events affecting user data are disclosed here honestly and promptly.
  • Vendor-domain verification and admin actions are audit-logged.
  • The security posture baseline we build to is OWASP ASVS 5.0 Level 2 where applicable.

Scope

bestaitoolix.com and its API surface. Reports about third-party tools we review belong with those vendors.