1. How to contact us
Send reports from an email address we can reply to. If you have a Gate AI account, prefer writing from the email on that account so we can verify context faster.
- Subject line: start with [Security], [Abuse], or [Data] so we can triage quickly.
- Include: what you observed, when (with timezone if possible), URLs or API paths involved, steps to reproduce, and any sample requests or screenshots that do not contain other users’ personal data.
- If you believe an incident is ongoing (active compromise or data leak), say so in the first line.
Reach us through your Gate AI account channels, or reply from the email on your account describing the issue. We will acknowledge reports that include enough detail to investigate.
2. Responsible disclosure
We welcome good-faith security research. Please give us a reasonable chance to investigate and fix issues before public disclosure.
- Do not access, modify, or delete data that is not yours.
- Do not run destructive tests (for example mass account creation, denial-of-service, or malware delivery).
- Do not social-engineer Gate AI staff or other users.
- Keep findings confidential until we confirm a fix or agree on a disclosure timeline.
Research that stays within these bounds will not, by itself, be treated as a Terms of Service violation. Activity outside good-faith testing may lead to account action under our Terms of Service.
3. What we usually need
- Affected product area (login, exam, reports, Pro, API).
- Impact (who could be affected; what an attacker gains).
- Reproduction steps or a minimal proof of concept.
- Your preferred contact and whether you want credit.
We do not currently operate a paid bug-bounty program. We still appreciate clear reports and will work with researchers who follow this process.
4. What happens after you report
- We triage severity and whether the issue is reproducible.
- We investigate, contain if needed, and plan a fix.
- We may ask follow-up questions; please keep the thread private.
- When resolved, we may confirm the fix. Public write-ups should wait until we agree the risk is addressed.
Response time depends on severity and completeness of the report. Critical, actively exploited issues are handled first.
5. Data concerns vs privacy requests
If you want a copy of your data, a correction, or account deletion under our normal privacy process, follow the Privacy Policy. Use this Security page when you suspect unauthorized access, a leak, or a vulnerability that exposes personal information.
6. Scope
In scope: Gate AI web application, authentication flows, exam and diagnostic APIs we operate, and related account or billing surfaces that process aspirant data.
Out of scope unless we ask otherwise: attacks on third-party providers (for example PostHog or future Google Sign-In) that do not involve a Gate AI misconfiguration; physical security; social-engineering of users; and speculative reports without a realistic impact.
7. Related policies
- Privacy Policy — how we collect and use data.
- Terms of Service — acceptable use, plans, and AI processing.