Security & Vulnerability Reporting
Effective 2026-09-13
Reporting a vulnerability
Email security@bestaitoolix.com with details and reproduction steps. We acknowledge reports within 3 business days. Please do not test against production user accounts, and give us a reasonable window to fix before public disclosure.
What we ask
- Test only with accounts you own.
- No automated scanning at disruptive volumes, no denial-of-service testing.
- Data you accidentally gain access to: report it, don't exfiltrate it.
Our commitments
- Security events affecting user data are disclosed here honestly and promptly.
- Vendor-domain verification and admin actions are audit-logged.
- The security posture baseline we build to is OWASP ASVS 5.0 Level 2 where applicable.
Scope
bestaitoolix.com and its API surface. Reports about third-party tools we review belong with those vendors.