Vulnerability Disclosure Policy
Last updated: September 14, 2026
Preneur LLC (“Elicitly”, “We”) welcomes good-faith security research into Our services and will work with You to understand, validate, and remediate what You find. This page is the policy referenced by Our security.txt (RFC 9116).
How to report
Email security@elicitly.ai with:
- the affected host, endpoint, or package;
- steps to reproduce (a proof of concept is ideal);
- the impact You believe the issue has.
Please use email — not public GitHub issues — for anything sensitive, so a fix can ship before details are public.
What to expect from Us
- We will acknowledge Your report within 5 business days.
- We will keep You informed as We validate and remediate the issue.
- We do not operate a paid bug bounty program and do not offer monetary rewards. We are happy to publicly credit You for a valid report if You wish.
Scope
In scope:
www.elicitly.ai,mcp.elicitly.ai, andapp.elicitly.ai;- the open-source packages
elicitlyand@elicitly/tools.
Out of scope — reports of the following do not qualify unless You demonstrate a concrete security impact:
- missing security headers, SPF/DKIM/DMARC configuration opinions, or other scanner output without a proof of concept;
- clickjacking on pages with no sensitive actions;
- software version disclosure;
- denial of service, volumetric, or brute-force findings;
- issues in third-party services We use (report those to the vendor).
Rules of engagement
- Test only with accounts and data You own; never access, modify, or delete another user’s data. If You encounter someone else’s data, stop immediately and report it.
- No denial-of-service testing, social engineering, phishing, or physical attacks.
- Give Us a reasonable window (90 days, or a coordinated date) to remediate before any public disclosure.
Safe harbor
We will not pursue legal action against You, or treat Your research as a violation of Our Terms and Conditions, for security research performed in good faith and within this policy — including its restriction on circumventing security measures, which this policy authorizes for that research. This safe harbor does not extend to actions outside this policy or to research affecting third parties.