Security Disclosure Policy
Last updated: 2026-09-15
Robot Networks Inc. welcomes reports that help keep Boardwalk and its users safe. This policy explains how to report a suspected vulnerability, how to conduct good-faith research, and what you can expect from us. It does not create a bug bounty or promise payment.
1. Report a vulnerability
Email security@boardwalk.cloud. Include a clear description, affected hostname or endpoint, reproduction steps, impact, relevant request identifiers, and a minimal proof of concept. Do not include API keys, passwords, payment-card information, or personal data that is not necessary to understand the issue. Our machine-readable contact is at /.well-known/security.txt.
2. Safe harbor
For research conducted in good faith and consistent with this policy, we will not initiate or support legal action against you for the research. We will treat compliant research as authorized under applicable computer-misuse and anti-circumvention laws and as permitted under the security-testing restriction in our Acceptable Use Policy.
If a third party brings legal action against you because of research conducted under this policy, we will take reasonable steps to make it known that your activity followed our policy. Safe harbor does not authorize violations of another person's rights or laws unrelated to access to our systems.
3. In scope
- Production services we operate under
boardwalk.cloud, including the marketing site, console, API, status page, and their production subdomains. admin.robotnet.works, limited to testing with an account and organization you own or have explicit authorization to use.- Authentication, authorization, tenant isolation, API-key handling, metering integrity, model visibility, repository access, and server-side request handling as implemented by Boardwalk.
4. Out of scope
- Systems operated by third parties, including AWS, RunPod, PlanetScale, Clerk, Stripe, Vercel, PostHog, and Hugging Face. Report vulnerabilities in their systems to them.
- Development, preview, local, or experimental environments.
- Denial of service, traffic flooding, stress testing, or tests that increase our costs.
- Social engineering, phishing, bribery, or physical attacks.
- Automated scanning without a demonstrated security impact, missing headers without an exploit, version banners, or reports based only on software-version comparison.
- Model behavior such as hallucination, bias, prompt injection within your own prompt, or generation of undesirable output, unless it crosses a Boardwalk authorization boundary, exposes another tenant's data, or compromises the Service.
5. Rules of engagement
- Use only accounts, organizations, keys, models, and payment methods you control.
- Keep traffic low and stop after confirming the minimum evidence needed.
- Do not access, alter, retain, or disclose another person's data. If you encounter it, stop immediately, do not download or share it, and tell us what happened.
- Do not disrupt the Service, degrade model capacity, or interfere with other users.
- Do not attempt persistence, lateral movement, data destruction, or extortion.
- Give us a reasonable opportunity to investigate and remediate before public disclosure.
6. Response targets
- Acknowledgment: within three business days.
- Initial triage: within ten business days.
- Remediation: based on severity, exploitability, and impact. We will share an expected timeline after triage when practical.
- Disclosure: coordinated with you, with a default window of 90 days after acknowledgment for unresolved issues unless active exploitation or user safety requires a different timeline.
7. Recognition
After remediation, we may publicly credit a researcher who requests recognition. We do not currently operate a paid bug-bounty program, and submission of a report does not create a right to payment.
8. Contact
Security reports and questions: security@boardwalk.cloud.