Trust

Security reporting

How to report vulnerabilities, abuse, or data concerns to Gate AI.

Last updated 1 August 2026

What to report

Three kinds of reports we want

Use this page when something looks wrong from a security, abuse, or data-protection perspective. Product bugs that do not affect safety or privacy are better sent through normal support channels.

  • Security vulnerabilitiesProduct & infrastructureReport

    Suspected bugs that could let someone access another user’s data, bypass authentication, escalate privileges, inject code, or disrupt the service. Prefer a clear reproduction path and impact summary — we can take it from there.

  • Abuse & misuseAccounts & contentReport

    Account takeover attempts, credential stuffing you observe against Gate AI, scraping or redistribution of our question bank, harassment via product features, or other misuse that harms aspirants or the platform.

  • Data & privacy concernsPersonal informationReport

    Accidental exposure of personal data, access to another aspirant’s reports or account details, or concerns about how Gate AI handles your information. For routine access or deletion requests, see our Privacy Policy; use this channel for suspected incidents.

1. How to contact us

Send reports from an email address we can reply to. If you have a Gate AI account, prefer writing from the email on that account so we can verify context faster.

  • Subject line: start with [Security], [Abuse], or [Data] so we can triage quickly.
  • Include: what you observed, when (with timezone if possible), URLs or API paths involved, steps to reproduce, and any sample requests or screenshots that do not contain other users’ personal data.
  • If you believe an incident is ongoing (active compromise or data leak), say so in the first line.

Reach us through your Gate AI account channels, or reply from the email on your account describing the issue. We will acknowledge reports that include enough detail to investigate.

2. Responsible disclosure

We welcome good-faith security research. Please give us a reasonable chance to investigate and fix issues before public disclosure.

  • Do not access, modify, or delete data that is not yours.
  • Do not run destructive tests (for example mass account creation, denial-of-service, or malware delivery).
  • Do not social-engineer Gate AI staff or other users.
  • Keep findings confidential until we confirm a fix or agree on a disclosure timeline.

Research that stays within these bounds will not, by itself, be treated as a Terms of Service violation. Activity outside good-faith testing may lead to account action under our Terms of Service.

3. What we usually need

  • Affected product area (login, exam, reports, Pro, API).
  • Impact (who could be affected; what an attacker gains).
  • Reproduction steps or a minimal proof of concept.
  • Your preferred contact and whether you want credit.

We do not currently operate a paid bug-bounty program. We still appreciate clear reports and will work with researchers who follow this process.

4. What happens after you report

  1. We triage severity and whether the issue is reproducible.
  2. We investigate, contain if needed, and plan a fix.
  3. We may ask follow-up questions; please keep the thread private.
  4. When resolved, we may confirm the fix. Public write-ups should wait until we agree the risk is addressed.

Response time depends on severity and completeness of the report. Critical, actively exploited issues are handled first.

5. Data concerns vs privacy requests

If you want a copy of your data, a correction, or account deletion under our normal privacy process, follow the Privacy Policy. Use this Security page when you suspect unauthorized access, a leak, or a vulnerability that exposes personal information.

6. Scope

In scope: Gate AI web application, authentication flows, exam and diagnostic APIs we operate, and related account or billing surfaces that process aspirant data.

Out of scope unless we ask otherwise: attacks on third-party providers (for example PostHog or future Google Sign-In) that do not involve a Gate AI misconfiguration; physical security; social-engineering of users; and speculative reports without a realistic impact.

7. Related policies